npm

localize-extract @1.0.0

Vulnerability report · Last retrieved from osv.dev August 19, 2026 at 12:52 PM UTC

Malicious

OSV ID

MAL-2026-14249

Ecosystem

npm

Summary

localize-extract@1.0.0 executes a postinstall script that collects host identifiers (os.hostname(), platform, arch, node version, package name, lifecycle event) and POSTs them as JSON to the hardcoded endpoint https://1zrgq9h2.instances.poc.jchunt.top/localize-extract at npm install time. The package name resembles @angular/localize and the tarball references the upstream angular/localize package.json, consistent with a dependency-confusion / typosquat probe. Data leaves the installer's machine to an attacker-chosen host without consent on install.

Source: amazon-inspector (265d3f1cc9dae0e1599e17054e0cebe1481224741d3c3dce5d78916feebd5da2)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.