Logo
npm

@fleetbo/svro@0.0.42

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 10:33 AM UTC

Malicious

OSV ID

MAL-2026-14586

Ecosystem

npm

Summary

The package ships two heavily obfuscated JavaScript files under dist/ — postinstall.cjs and cli.cjs — using hex-mangled identifiers (_0x56260b, _0x12d644, etc.) characteristic of javascript-obfuscator output. The corresponding non-minified variants (dist/postinstall.js and dist/cli.js) combine require('child_process') with outbound POST HTTP calls at the top level of a postinstall entry point, meaning the code executes automatically on npm install and can both spawn processes on the installer's host and send data to a network endpoint. Obfuscation of a postinstall lifecycle script that has both process-spawning and HTTP-POST primitives is not consistent with any legitimate build, native-binary fetch, or telemetry pattern — legitimate postinstalls do not need to hide their control flow. The combination of automatic install-time execution, deliberate code obfuscation, and reachable child_process + outbound HTTP primitives is the fingerprint of an install-time dropper or exfiltration payload.

Source: amazon-inspector (0d86373813cd4d2b65edb11f6a3f352ad81a55e7de0444884f66b0adb482e661)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.