@testrelic/appium-analytics@1.1.1-next.88
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 10:33 AM UTC
OSV ID
MAL-2026-15647
Ecosystem
npm
Summary
The package registers scripts/postinstall.cjs as an npm postinstall hook. Alongside a benign-looking config-writer, the script contains an obfuscation layer that uses a custom Fisher-Yates-style permutation (Dbv) to reconstruct the string 'constructor' from a scrambled seed, resolves it against a function object to obtain the Function constructor, decodes a scrambled payload body, and invokes Function('', <decoded>)() at install time. Before invocation the wrapper stashes require, module, __dirname and __filename onto global under obfuscated keys so the decoded body can reach Node's module and filesystem APIs from within the Function() scope. The dist/ bundle additionally imports child_process and issues POST/GET calls from multiple files (dist/cli.cjs, dist/index.cjs, dist/service.cjs). No legitimate analytics/config bootstrap requires decoding an opaque scrambled string and executing it through Function.constructor, and the deliberate scope-escape scaffolding is characteristic of install-time droppers. The payload runs automatically on npm install on every installer machine.
Source: amazon-inspector (0b67d6f23451a756c154b86142f91615f5c08c415166c1f66216c8c83d74cbeb)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.