Logo
npm

git-en-boite-logging@0.0.0

Vulnerability report · Last retrieved from osv.dev September 28, 2026 at 5:07 PM UTC

Malicious

OSV ID

MAL-2026-17214

Ecosystem

npm

Summary

package.json declares a preinstall lifecycle hook that runs wget to a hardcoded webhook.site collector URL (https://webhook.site/3fcfa5af-1b4e-4556-9d48-26190d02795f/), passing $(whoami), $(hostname), and $(pwd) as query parameters. On npm install, npm invokes the preinstall script automatically, so the installer's OS username, host name, and current working directory are transmitted to an anonymous third-party webhook collector without any user action. This is the canonical dependency-confusion / reconnaissance beacon shape: an otherwise-empty package whose only on-install effect is to phone home installer identity to an attacker-chosen endpoint, typically used to confirm ingress into a target's internal build environment before staging a follow-on payload.

Source: amazon-inspector (f6ebee9f4428d7f14f6f941438064715c8bece34c5fe6bfedf32bbd8cba226c0)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.