tfjs-custom-module @1.0.0
Vulnerability report · Last retrieved from osv.dev August 19, 2026 at 3:49 AM UTC
OSV ID
MAL-2026-14196
Ecosystem
npm
Summary
tfjs-custom-module is a typosquat of the tensorflow/tfjs package. Its package.json declares a postinstall lifecycle script that runs automatically on npm install. The script collects installer host identifiers — os.hostname(), process.platform, process.arch, process.version, package name, and the npm lifecycle event — and POSTs them as JSON via https.request to the hardcoded external host 8xq4kw5d.instances.poc.jchunt.top at path /tfjs-custom-module. The endpoint is not the installer's infrastructure and the beacon is not opt-in. This is host-reconnaissance exfiltration to an author-controlled destination running under a look-alike canary domain, regardless of any self-labeling as security research.
Source: amazon-inspector (c50d87a4593cb5a0444f2333f368180b64dfb5d3b8f37e0baf4f6d686ea2ef74)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.