Logo
npm

model-poc-suhail@1.0.14

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC

Malicious

OSV ID

MAL-2026-3030

Ecosystem

npm

Summary

Package ships poc.js which requires child_process and spawns /bin/sh, connecting its stdin/stdout to a TCP socket at 0.tcp.in.ngrok.io:10023. This gives whoever controls that ngrok tunnel an unauthenticated interactive shell on the installer's host. Execution is triggered automatically by the package.json postinstall lifecycle hook ("postinstall": "node poc.js"), so the reverse shell fires on every npm install.

Source: amazon-inspector (5632cd6f241c640005252e66d1d85f09ba30b019890cb696ada78760ed8e6fed)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.