niksinnkatalapp@100.0.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17435
Ecosystem
npm
Summary
The package declares a preinstall hook that runs setup.js on npm install. setup.js collects host identifiers (os.hostname(), os.userInfo().username, process.cwd(), platform, arch, node version, and the configured npm registry) and POSTs them as JSON, together with a hardcoded correlation token, to https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook. The advertised purpose is a trivial celsius-to-fahrenheit conversion, which does not require telemetry or network activity. The package name and 100.0.0 version pin are consistent with a dependency-confusion lure intended to win resolution against an internal package name and beacon out from build environments that install it.
Source: amazon-inspector (25ce51139798c658f3018f19912e889df1b0ce31025a6236a473d959b12ef0d9)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.