Logo
npm

etoro-charts@999.0.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 7:32 AM UTC

Malicious

OSV ID

MAL-2026-16118

Ecosystem

npm

Summary

On npm install, preinstall.js runs automatically and sends the installer's hostname, username, platform, and current working directory via HTTP GET to http://209.126.81.147/etoro-nuget-verify1f8eaa57a875/npm/v2/<host>/<user>/<platform>/<cwd>, then executes whoami; id; hostname -f (or whoami /all on Windows) via child_process and POSTs the command output to the same hardcoded bare-IP endpoint over plain HTTP. The package.json advertises the package as an Internal service client library at version 99.0.0 with no real functional code beyond the preinstall hook, and the beacon path segment etoro-nuget-verify... targets an internal eToro namespace, matching the dependency-confusion recon pattern.

Source: amazon-inspector (e44aff5a1a0b68ff9c9b3456693ef1b8266dce7001dd8b6ff56bed428bbc7c5a)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.