npm

preinstall-hook-webhook-callback-demo @1.0.1

Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 2:31 AM UTC

Malicious

OSV ID

MAL-2026-14016

Ecosystem

npm

Summary

package.json declares a preinstall lifecycle script that contacts webhook.site, an ephemeral request-capture service commonly used as an attacker-controlled exfiltration sink. The hook fires automatically on npm install before any user interaction, and webhook.site is not a first-party or documented destination for any legitimate build or runtime purpose of this package. The combination of an auto-executing preinstall script wired to an out-of-band capture endpoint is the shape of installer-side data exfiltration / callback beaconing at install time.

Source: amazon-inspector (d6e707d55368c2628038e0efaac35629fba6dbd520e66a7e29f9c6a86c69b2e1)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.