vishal_312pkg@1.0.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 10:33 AM UTC
OSV ID
MAL-2026-16006
Ecosystem
npm
Summary
package.json declares a preinstall lifecycle script that runs on npm install and issues a wget request to https://webhook.site/ea0ca859-424d-4cc5-9210-62f7e25692a1/ carrying the installer's username ($(whoami)), current working directory ($(pwd)), and hostname ($(hostname)) as querystring parameters. The destination is a third-party request-inspection collector hardcoded in the manifest, unrelated to any documented package purpose. This is the canonical dependency-confusion / reconnaissance beacon shape: automatic execution at install time, unconditional outbound network to an attacker-controlled endpoint, and disclosure of installer host identifiers that identify internal environments and users.
Source: amazon-inspector (74d38dada8ec3921b4a3f69e7d44b5f5b54d345ff8f9581d34007a3e68679da4)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.