Logo
npm

spoint@0.1.700

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 3:37 AM UTC

Malicious

OSV ID

MAL-2026-13725

Ecosystem

npm

Summary

Static keyword matches fired on the co-occurrence of tokens like 'curl', 'ping', 'POST', and 'GET' inside SDK/orchestrator source files (bin/room-orchestrator-boot.js, src/sdk/RoomOrchestrator.js, src/sdk/ServerAPI.js, src/sharding/RegionRouter.js). These are consistent with an orchestrator/routing SDK that performs latency probes and HTTP requests against its own service endpoints — the shape of a room/region networking client, not of an exfiltration primitive. No specific installer-side secret is shown being read (no ~/.aws, ~/.ssh, ~/.npmrc, env-var scraping, browser profile access), no hardcoded attacker C2 destination is named in evidence, and no lifecycle hook or top-level require-time execution path invoking these calls is demonstrated. Keyword co-occurrence in networking code is the shared shape of legitimate HTTP clients and cannot by itself establish exfiltration intent.

Source: amazon-inspector (4c32e6b328bf731b6269e720e0fda2dec5264452ef04d406fde5296413424525)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.