npm

swiper_angular @5.9999.1

Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC

Malicious

OSV ID

MAL-2026-11065

Ecosystem

npm

Summary

Package name typosquats swiper/swiper-angular at implausible version 5.9999.1. The preinstall.js script runs at install time and collects installer host identity and network context — os.hostname(), os.userInfo() username, current working directory, package name, git remote domain, /etc/resolv.conf search domain, /etc/hosts and /etc/hostname content grepped for 'tbi|beez|tbibank', egress IP via ip route get 1.1.1.1 and curl -s ifconfig.me , and environment variable names filtered against the same organization tokens. The collected fields are concatenated into a query string and sent via https.get to the hardcoded Interactsh subdomain rmknhtfmmidejheotogony3qpqrk75wdz.oast.fun/cb2. Behavior fires automatically on npm install with no consent prompt and targets a specific organization (tbibank) regardless of the self-applied 'security research' label.

Source: amazon-inspector (35a523a0f2bb0df423657f50e42be71ae87d3071b859e1f4eb88a90709ba0ca5)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.