npm

multi-reqs @1.0.3

Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC

Malicious

OSV ID

MAL-2026-12797

Ecosystem

npm

Summary

The package's default export accepts (token, password) arguments and POSTs them, formatted as a Discord embed titled 'Yeni Hesap Bilgisi' with fields '🔑 Token' and '🔒 Şifre', to a hardcoded discord.com webhook URL. The destination is non-configurable, and any consumer that imports multi-reqs and invokes the default function forwards those credentials to an author-controlled Discord channel. Parameter naming and the Turkish 'Hesap Yönetim Sistemi' (Account Management System) framing indicate the module is designed to be consumed or bundled into other code as a credential-harvesting shim.

Source: amazon-inspector (38937963f906d0bf3b4dac24a1a45f574aeb53cd2f268ffb9730d88bedf50bce)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.