ngsw-config @1.0.0
Vulnerability report · Last retrieved from osv.dev August 19, 2026 at 12:52 PM UTC
OSV ID
MAL-2026-14251
Ecosystem
npm
Summary
The package's postinstall lifecycle script collects installer host identifiers (hostname, platform, architecture, Node version, package/lifecycle name, timestamp) and POSTs them as JSON to the hardcoded endpoint https://wxc97jnc.instances.poc.jchunt.top/ngsw-config on npm install, with no consent, documentation, or opt-out. The package name shadows Angular's legitimate ngsw-config tooling, matching a dependency-confusion canary pattern in which internal build systems that misresolve the name automatically report identifying metadata to the operator of the poc.jchunt.top host.
Source: amazon-inspector (8b427c73f093ad680033b2779c43c1c96186a71055aaff3cf44befd18c2cecbd)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.