Logo
npm

com.db.autobahn.notification-center-electron@88.88.2

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 2:33 PM UTC

Malicious

OSV ID

MAL-2026-15590

Ecosystem

npm

Summary

package.json declares preinstall and postinstall lifecycle scripts that automatically run curl on npm install to send installer identity (whoami, hostname, $PWD, timestamp) as query-string parameters to a long-random-label third-party host (da9nfhavbsgte1dqq8fgrbb7fyfekc37i.cyowl.com) over plain HTTP. The package name (com.db.autobahn.notification-center-electron) and implausibly high version (88.88.1) are consistent with a dependency-confusion lure targeting an internal scope; installing this package leaks host reconnaissance data to an external endpoint.

Source: amazon-inspector (4ae376efc666d8e07f356f9f3cbafe2dfc99e221a150ff96548db4a2b91bb452)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.