npm

verify-cli @99.0.0

Vulnerability report · Last retrieved from osv.dev August 13, 2026 at 4:27 AM UTC

Malicious

OSV ID

MAL-2026-13882

Ecosystem

npm

Summary

package.json declares preinstall: node index.js , which runs automatically on npm install . index.js shells out via child_process and curl to POST the installer's whoami , hostname , and id output along with base64-encoded contents of /etc/passwd , /etc/hosts , and (if readable) /etc/shadow to a hardcoded out-of-band interactsh/OAST endpoint at 5f8a1ed70fb7761d678agw9bucryyyyyb.oast.site . Package metadata shows an implausible version (99.0.0), placeholder description ("Nodejs SDK for Redacted"), and a nonexistent dependency, consistent with a dependency-confusion / typosquat beacon rather than a legitimate SDK.

Source: amazon-inspector (081d3a8717b3f05f688cdde25d2b0de315dd9b1f400382e0db00d53f8ca82d6b)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.