OSV ID
MAL-2026-14591
Ecosystem
npm
Summary
The package has no advertised functionality (empty description, self-referential dependency on its own name at ^9.9.9). Its package.json declares both preinstall and postinstall lifecycle scripts that execute index.js, which reads os.hostname() and issues an HTTP GET to https://eo8f3m3ho26a0nm.m.pipedream.net/cacao1 with the hostname included as a query parameter. Installing the package therefore causes the installer's hostname to be transmitted to a hardcoded third-party collector controlled by the package author. The structure (empty description, self-dependency, lifecycle-triggered beacon to a pipedream.net collector, unusual 9.9.9 version) matches a dependency-confusion beacon rather than a functional library.
Source: amazon-inspector (403a43aab3b982d17c5c01d7df45149d796e7185f4137bf4a92675351a1b50e8)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.