real-router-utils@1.0.0
Vulnerability report · Last retrieved from osv.dev September 3, 2026 at 12:51 AM UTC
OSV ID
MAL-2026-15825
Ecosystem
npm
Summary
package.json declares a preinstall script that runs an inline node command reading the installer's OS hostname, username, and current working directory and sending them as query parameters to a hardcoded webhook.site collector URL (https://webhook.site/e32d3b8a-a5df-40cc-ae60-7a8343b581e4). The request fires automatically on npm install, before any user interaction, and the destination is an anonymous ephemeral webhook endpoint unrelated to any documented package purpose.
Source: amazon-inspector (f91fd520ae94997277ef7d591d30dc728b895611fd45b890e2ec1a68233e29a8)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.