etoro-aggregator@999.0.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC
OSV ID
MAL-2026-16111
Ecosystem
npm
Summary
The package's preinstall.js lifecycle script executes automatically on npm install and performs reconnaissance on the installer host. It collects hostname, username, current working directory, platform, and the output of OS commands including whoami /all, ipconfig /all / ifconfig, tasklist / ps aux, directory listings of /, C:\, and the user's home, and a dump of environment variables. The collected data is transmitted via HTTP GET and POST to the hardcoded bare IP endpoint http://209.126.81.147/etoro-nuget-verify1f8eaa57a875/v4/.... The package's declared main is an empty stub and its description ("Internal service client library") combined with the implausibly high version number 99.0.2 is consistent with a dependency-confusion attack targeting an internal etoro-aggregator name. The manifest plus the preinstall script constitute the entire payload; installing the package leaks installer host identity, network configuration, filesystem structure, and environment variables (which routinely contain credentials and tokens) to an attacker-controlled endpoint.
Source: amazon-inspector (d7d5f0fb8c06c23afad28686a3d3d689dfc5a3786c73bff2c569fd8b55f2b4ad)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.