Logo
npm

kalasnik-npm-simple-test@1.0.0

Vulnerability report · Last retrieved from osv.dev September 28, 2026 at 8:08 PM UTC

Malicious

OSV ID

MAL-2026-17206

Ecosystem

npm

Summary

The package's postinstall script send_data.js runs automatically on npm install. It reads C:\temp\test.txt from the installer's filesystem and POSTs the contents over plain HTTP to a hardcoded remote endpoint at 35.178.197.251:8080. Package metadata ("Simplified test", author "Purple", UNLICENSED) is consistent with a PoC exfiltration harness rather than a legitimate library.

Source: amazon-inspector (f1463688412306d5d6f791bb036bea59aeb7251a3044a52c57119768f27cd463)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.