OSV ID
MAL-2026-11043
Ecosystem
npm
Summary
supplyhub@1.0.1 ships a postinstall.js that runs automatically on npm install and collects installer host identifiers (os.hostname(), os.userInfo().username, process.cwd(), pid, platform, arch, node version) along with CI-related environment variables (CI, RENOVATE_VERSION), then transmits them as query parameters to a hardcoded webhook.site endpoint (https://webhook.site/3c9418b3-cacd-403d-b42e-e9e4a9508fe3) using https.get with http and execSync('curl...' || wget...) fallbacks. The package.json description self-labels this as a dependency-confusion PoC targeting the 'Travix supplyhub' name, but the tarball is published to public npm and will execute the install-time beacon against any installer that resolves this name, including unrelated users who typo or whose internal builds dependency-confuse into it.
Source: amazon-inspector (e0d6286c7aa72597cf47fca7e9db99799909ceba09490f4a185b359e71f63590)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.