Logo
npm

getd-pantallas-cliente@0.0.1

Vulnerability report · Last retrieved from osv.dev September 6, 2026 at 5:01 AM UTC

Malicious

OSV ID

MAL-2026-5468

Ecosystem

npm

Summary

On npm install, postinstall.js collects os.hostname(), os.userInfo().username, os.platform(), process.cwd(), and CI/build environment variables and sends them as URL query parameters via HTTPS GET to an anonymous webhook.site endpoint (https://webhook.site/18dc4281-d366-438a-9186-76fbcd56ade5). Errors are silently swallowed; there is no opt-in or disclosure. The package's own package.json description self-identifies as a typosquat placeholder for the @getd/* scope, so any installer who mistypes a scoped package name has their machine fingerprinted and shipped to a third-party endpoint outside their control. Regardless of the author's stated 'defensive research' framing, the on-install behavior is unconsented exfiltration of installer-identifying data to an anonymous, ephemeral destination.

Source: amazon-inspector (89a26267435645776aa984be114d5c657e63fa9937ff044e5ddd24943b28ea6e)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.