bender-rspack-config@1.0.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC
OSV ID
MAL-2026-16221
Ecosystem
npm
Summary
package.json declares a preinstall lifecycle script that runs wget against a hardcoded webhook.site URL, embedding $(whoami), $(pwd), and $(hostname) as query-string parameters. The request fires automatically on npm install, transmitting the installer's username, working-directory path, and hostname to an author-controlled collector at webhook.site/9d385aa8-875e-48b6-938c-6c0f5a0e8319/. The behavior is self-labeled as a dependency-confusion proof of concept, but the shipped code is a functioning identity-beacon regardless of framing.
Source: amazon-inspector (3a6997cea54ae81d1addcb41ddac29e94923dfa1042265253c555cb4945ad5b4)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.