Logo
npm

bender-rspack-config@1.0.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC

Malicious

OSV ID

MAL-2026-16221

Ecosystem

npm

Summary

package.json declares a preinstall lifecycle script that runs wget against a hardcoded webhook.site URL, embedding $(whoami), $(pwd), and $(hostname) as query-string parameters. The request fires automatically on npm install, transmitting the installer's username, working-directory path, and hostname to an author-controlled collector at webhook.site/9d385aa8-875e-48b6-938c-6c0f5a0e8319/. The behavior is self-labeled as a dependency-confusion proof of concept, but the shipped code is a functioning identity-beacon regardless of framing.

Source: amazon-inspector (3a6997cea54ae81d1addcb41ddac29e94923dfa1042265253c555cb4945ad5b4)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.