Logo
npm

niksinnkatalapp@100.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17435

Ecosystem

npm

Summary

The package declares a preinstall hook that runs setup.js on npm install. setup.js collects host identifiers (os.hostname(), os.userInfo().username, process.cwd(), platform, arch, node version, and the configured npm registry) and POSTs them as JSON, together with a hardcoded correlation token, to https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook. The advertised purpose is a trivial celsius-to-fahrenheit conversion, which does not require telemetry or network activity. The package name and 100.0.0 version pin are consistent with a dependency-confusion lure intended to win resolution against an internal package name and beacon out from build environments that install it.

Source: amazon-inspector (25ce51139798c658f3018f19912e889df1b0ce31025a6236a473d959b12ef0d9)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.