Logo
npm

stretchshop@0.7.5

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 3:37 AM UTC

Malicious

OSV ID

MAL-2026-13460

Ecosystem

npm

Summary

package.json declares a postinstall hook that runs node demo/demo.js base, which shell-invokes git clone https://github.com/Wradgio/StretchShop-demo-data.git at mutable HEAD (no commit SHA, no tag, no integrity check) and then childProcess.forks db/demo_data.js from the freshly cloned tree. The cloned repository is owned by the personal GitHub account Wradgio, which does not match the package's publisher scope StretchShop. Whoever controls that GitHub account can push arbitrary JavaScript to the default branch and have it executed on every fresh top-level install of stretchshop@0.7.5.

Source: amazon-inspector (479c1238e6380db5463eb3755b980f963d269b2b0874d464b9e1b3b65bd03f60)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.