insomnia-plugin-api-lint-helper@1.0.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC
OSV ID
MAL-2026-17561
Ecosystem
npm
Summary
index.js, the package's main entry, runs at require() time with no user interaction. On load it spawns OS-native calculator processes via child_process.exec ('calc.exe' on Windows, 'open -a Calculator' on macOS, 'gnome-calculator' on Linux) to demonstrate arbitrary code execution; writes a marker file to the user's Desktop (INSOMNIA_RCE_PROOF.txt); and serializes the full process.env object with JSON.stringify and emits it to the console, disclosing any tokens, API keys, and other secrets present in the environment of the host process (typically Insomnia on a developer machine). The source comments self-identify the module as a proof-of-concept remote code execution payload targeting Insomnia's plugin loader. The arbitrary-exec, filesystem write outside the package directory, and bulk environment enumeration all fire unconditionally at load.
Source: amazon-inspector (f3572e41f2e2e83a3156c1b24bf8684c0149a508e45626e80c592657cfb475ba)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.