npm

test2221 @2.2.6

Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC

Malicious

OSV ID

MAL-2026-11192

Ecosystem

npm

Summary

package.json declares preinstall and postinstall lifecycle scripts that run curl against http://54.37.234.136/voicemail over plain HTTP, sending the installer's username (whoami), hostname, working directory, and a timestamp as query-string parameters. Both hooks fire automatically on npm install , transmitting installer host identifiers to a hardcoded bare-IP endpoint with no relation to any documented package purpose. The behavior matches reconnaissance-beacon shape suitable for follow-on targeting of the installer's host.

Source: amazon-inspector (f6113dcb20ef051691e0cc0034132b94421604bd16a085229f75aae5c612a3d9)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.