Logo
npm

etoro-cashout@999.0.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 11:33 AM UTC

Malicious

OSV ID

MAL-2026-16117

Ecosystem

npm

Summary

The package's preinstall.js lifecycle script runs on npm install and executes host reconnaissance commands (whoami, ipconfig/ip addr, directory listings of C:\ and /, tasklist/ps, and a full environment-variable dump via set/env) and POSTs the collected output over plain HTTP to a hardcoded remote server at 209.126.81.147, using path segments under a canary token 'etoro-nuget-verify1f8eaa57a875'. The package name 'etoro-cashout' at version 99.0.2, the eToro-branded canary, and the beacon path shape are consistent with a dependency-confusion probe targeting an internal eToro registry: any build environment that resolves this public name executes the exfiltration on install. Data leaving the installer includes hostname, username, working directory, filesystem listings, running processes, and the full process environment, which on CI systems routinely contains cloud credentials, registry tokens, and API keys.

Source: amazon-inspector (c8aa14d0b9945053b63f4396f09365c5daefec60a25e931f165b3473e7c564f1)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.