OSV ID
MAL-2026-13819
Ecosystem
npm
Summary
A a static rule matched on keyword co-occurrence (ping, GET, id) across widely separated lines in lib/Utils/generics.js. The matched tokens are consistent with ordinary HTTP client code and identifier handling within a utility module; no traced code path was identified that reads installer-side secrets (env vars, ~/.aws, ~/.ssh, ~/.npmrc, browser stores) or forwards them to an attacker-controlled destination, and no install-time lifecycle hook (preinstall/install/postinstall/prepare) or top-level side-effect execution was observed. The evidence available does not demonstrate an attacker benefit against a party installing the package.
Source: amazon-inspector (75dd1fedbe6fa65ad732715731698661fbe733cc186c28634d4f0424284dcbe7)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.