Logo
npm

github-policy-bot@1.0.0

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 4:37 AM UTC

Malicious

OSV ID

MAL-2026-14245

Ecosystem

npm

Summary

On npm install, the package's postinstall script collects host identifiers (os.hostname(), platform, arch, node version, package name, npm lifecycle event) and POSTs them as JSON to the hardcoded host vlfl47tl.instances.poc.jchunt.top at path /github-policy-bot. The outbound request is fail-silent (error handler swallows failures) and short-timeout, consistent with a beacon. The package name shadows the Google-owned js-github-policy-bot repository path referenced in the tarball's source.txt, and the package.json author is a placeholder (r00tdaddy) with a self-declared 'security research canary' purpose — an author-controlled label that does not change the behavior. Installing this package causes unsolicited disclosure of the installer's hostname and environment metadata to a third-party endpoint the installer did not configure.

Source: amazon-inspector (87b8742a99002975ebaced2478673108f4f442e5ac7878651edeb8346702f132)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.