Logo
npm

etoro-aggregator@999.0.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC

Malicious

OSV ID

MAL-2026-16111

Ecosystem

npm

Summary

The package's preinstall.js lifecycle script executes automatically on npm install and performs reconnaissance on the installer host. It collects hostname, username, current working directory, platform, and the output of OS commands including whoami /all, ipconfig /all / ifconfig, tasklist / ps aux, directory listings of /, C:\, and the user's home, and a dump of environment variables. The collected data is transmitted via HTTP GET and POST to the hardcoded bare IP endpoint http://209.126.81.147/etoro-nuget-verify1f8eaa57a875/v4/.... The package's declared main is an empty stub and its description ("Internal service client library") combined with the implausibly high version number 99.0.2 is consistent with a dependency-confusion attack targeting an internal etoro-aggregator name. The manifest plus the preinstall script constitute the entire payload; installing the package leaks installer host identity, network configuration, filesystem structure, and environment variables (which routinely contain credentials and tokens) to an attacker-controlled endpoint.

Source: amazon-inspector (d7d5f0fb8c06c23afad28686a3d3d689dfc5a3786c73bff2c569fd8b55f2b4ad)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.