etoro-auth@999.0.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC
OSV ID
MAL-2026-16114
Ecosystem
npm
Summary
The package's preinstall.js runs automatically on npm install and collects host identifiers (os.hostname(), os.userInfo().username, process.cwd(), process.platform), sending them via HTTP GET to a hardcoded bare-IP endpoint at http://209.126.81.147/etoro-nuget-verify1f8eaa57a875/npm/v2/<hostname>/<user>/<platform>/<cwd>. It then executes whoami, id, and hostname -f (or whoami /all on Windows) via child_process and POSTs the command output to the same endpoint. The package's main entry (index.js) is empty; the only shipped behavior is the reconnaissance beacon. The package name and version (etoro-auth@99.0.0) together with the URL path segment etoro-nuget-verify fit a dependency-confusion probe targeting eToro's internal namespace, with the high version number used to win resolution against an internal package of the same name.
Source: amazon-inspector (385c1c361c59557137d095062a9f767a4c0cd0a1ef78b0b26e4654147e137e3c)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.