Logo
npm

sorrawit-dev-helper@1.0.0

Vulnerability report · Last retrieved from osv.dev September 21, 2026 at 7:43 AM UTC

Malicious

OSV ID

MAL-2026-16344

Ecosystem

npm

Summary

package.json declares a postinstall lifecycle script that runs automatically on npm install. The script reads /tmp/flag.txt from the installer's machine and sends its URL-encoded contents as a query parameter to a hardcoded ngrok tunnel at https://ca37-49-237-83-218.ngrok-free.app/. The destination is an ephemeral tunnel host unrelated to any legitimate publisher, and the read+exfil fires without user interaction. The behavior matches install-time credential/file exfiltration with a concrete installer-side data source and a concrete attacker-controlled destination.

Source: amazon-inspector (c64040dcfbbdb6ce434caf3cd5bd2baa518cc00970281a69f5309d57a4621233)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.