com.db.autobahn.notification-center-electron@88.88.2
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 2:33 PM UTC
OSV ID
MAL-2026-15590
Ecosystem
npm
Summary
package.json declares preinstall and postinstall lifecycle scripts that automatically run curl on npm install to send installer identity (whoami, hostname, $PWD, timestamp) as query-string parameters to a long-random-label third-party host (da9nfhavbsgte1dqq8fgrbb7fyfekc37i.cyowl.com) over plain HTTP. The package name (com.db.autobahn.notification-center-electron) and implausibly high version (88.88.1) are consistent with a dependency-confusion lure targeting an internal scope; installing this package leaks host reconnaissance data to an external endpoint.
Source: amazon-inspector (4ae376efc666d8e07f356f9f3cbafe2dfc99e221a150ff96548db4a2b91bb452)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.