model-poc-suhail@1.0.14
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC
OSV ID
MAL-2026-3030
Ecosystem
npm
Summary
Package ships poc.js which requires child_process and spawns /bin/sh, connecting its stdin/stdout to a TCP socket at 0.tcp.in.ngrok.io:10023. This gives whoever controls that ngrok tunnel an unauthenticated interactive shell on the installer's host. Execution is triggered automatically by the package.json postinstall lifecycle hook ("postinstall": "node poc.js"), so the reverse shell fires on every npm install.
Source: amazon-inspector (5632cd6f241c640005252e66d1d85f09ba30b019890cb696ada78760ed8e6fed)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.