live-detection-dashboard@100.0.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17434
Ecosystem
npm
Summary
The package's preinstall lifecycle script fires automatically on npm install and issues an HTTPS POST to the hardcoded endpoint https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook, carrying a JSON body composed of installer-side identifiers: os.hostname(), os.userInfo().username, process.cwd(), process.platform, process.arch, the Node.js version, and the configured npm registry, along with a static token. The advertised functionality of the package is a trivial random-hex helper, which does not require network activity or host/user identifiers, and the data flow is neither documented nor caller-configurable. The destination is an author-controlled AWS API Gateway. Package version 100.0.0 combined with a minimal declared purpose and an install-time beacon is consistent with a dependency-confusion / reconnaissance payload targeting internal build environments.
Source: amazon-inspector (5d6433d908aabd1002455fbed5a7afdf730c557f6c072fed817d76cad31a5ccb)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.