Logo
npm

tiny-viewport-unit-calc@1.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17528

Ecosystem

npm

Summary

The package ships thunderboltRegistry.js, a module that imports Node's child_process primitives and executes whoami plus repeated ping commands against external hostnames, with POST calls present in the same file. The pattern (whoami capture + repeated ping-based beacons + outbound POSTs) is host-reconnaissance and DNS/ICMP-channel exfiltration shape, directed from the installer's machine to an external endpoint. The behavior is unrelated to the package's advertised purpose (a trivial viewport-unit calculator) and provides no functionality to a consumer; its only effect is to leak host identity information off-host when the module is loaded or invoked.

Source: amazon-inspector (34c221d8f8f0fedded27bfc22763912ffd96e9f3d1b2c08932e054ed418f493e)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.