github-policy-bot@1.0.0
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 4:37 AM UTC
OSV ID
MAL-2026-14245
Ecosystem
npm
Summary
On npm install, the package's postinstall script collects host identifiers (os.hostname(), platform, arch, node version, package name, npm lifecycle event) and POSTs them as JSON to the hardcoded host vlfl47tl.instances.poc.jchunt.top at path /github-policy-bot. The outbound request is fail-silent (error handler swallows failures) and short-timeout, consistent with a beacon. The package name shadows the Google-owned js-github-policy-bot repository path referenced in the tarball's source.txt, and the package.json author is a placeholder (r00tdaddy) with a self-declared 'security research canary' purpose — an author-controlled label that does not change the behavior. Installing this package causes unsolicited disclosure of the installer's hostname and environment metadata to a third-party endpoint the installer did not configure.
Source: amazon-inspector (87b8742a99002975ebaced2478673108f4f442e5ac7878651edeb8346702f132)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.