etoro-charts@999.0.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 7:32 AM UTC
OSV ID
MAL-2026-16118
Ecosystem
npm
Summary
On npm install, preinstall.js runs automatically and sends the installer's hostname, username, platform, and current working directory via HTTP GET to http://209.126.81.147/etoro-nuget-verify1f8eaa57a875/npm/v2/<host>/<user>/<platform>/<cwd>, then executes whoami; id; hostname -f (or whoami /all on Windows) via child_process and POSTs the command output to the same hardcoded bare-IP endpoint over plain HTTP. The package.json advertises the package as an Internal service client library at version 99.0.0 with no real functional code beyond the preinstall hook, and the beacon path segment etoro-nuget-verify... targets an internal eToro namespace, matching the dependency-confusion recon pattern.
Source: amazon-inspector (e44aff5a1a0b68ff9c9b3456693ef1b8266dce7001dd8b6ff56bed428bbc7c5a)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.