Logo
npm

etoro-analytics@999.0.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC

Malicious

OSV ID

MAL-2026-16112

Ecosystem

npm

Summary

etoro-analytics@99.0.2 ships a preinstall lifecycle script (preinstall.js) that automatically runs on npm install. The script collects installer host identifiers (hostname, username, cwd, platform) and issues an initial HTTP GET to http://209.126.81.147/etoro-nuget-verify1f8eaa57a875/v4/<host>/<user>/<platform>/<cwd>. It then invokes child_process.execSync on platform-branched reconnaissance commands (whoami /all, ipconfig /all, tasklist on Windows; whoami, ifconfig, ps aux, env on POSIX) plus home/root directory listings and POSTs the output back to the same hardcoded bare-IP endpoint over plain HTTP. The package name, implausibly high version number (99.0.2), and canary-token URL path are consistent with a dependency-confusion beacon targeting an internal etoro package namespace.

Source: amazon-inspector (bfe27d37497e77c8f0eca9105a6b64c646c7ef1439c05ec50edaf40215037f92)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.