sm-admin @99.0.1
Vulnerability report · Last retrieved from osv.dev August 24, 2026 at 9:16 AM UTC
OSV ID
MAL-2026-14393
Ecosystem
npm
Summary
Package sm-admin@99.0.0 defines preinstall and postinstall lifecycle scripts that issue plain-HTTP GET requests to a hardcoded bare-IP endpoint at http://16.192.173.5/sm-admin/pre and http://16.192.173.5/sm-admin/post. Installing the package causes the installer host to contact this endpoint, revealing that the internal-sounding name 'sm-admin' resolved on that machine and disclosing the installer's source IP to the operator of that endpoint. The destination is a bare IPv4 over cleartext HTTP with no relationship to any publisher, and the elevated version number (99.0.0) together with the callback shape is characteristic of a dependency-confusion probe against a private-registry name. The endpoint is attacker-controlled and unauthenticated, so the response body served to preinstall/postinstall could change at any time.
Source: amazon-inspector (fa2741ebbd0df8c6f349a4d34361cc3d814fe878f3f4521fd771a855cfdc152b)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.