Logo
npm

voicemail@1.0.2

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 7:32 AM UTC

Malicious

OSV ID

MAL-2026-12496

Ecosystem

npm

Summary

package.json declares both preinstall and postinstall lifecycle scripts that invoke curl against a hardcoded webhook.site endpoint (https://webhook.site/d80b4602-8a87-4693-8510-6ff77c62788e/blots) with query parameters carrying the installer's username ($(whoami)), hostname ($(hostname)), current working directory ($PWD), and a timestamp. The beacon fires automatically on npm install without user consent, sending host and identity reconnaissance to an attacker-controlled collector. The package provides no legitimate functionality corresponding to this network activity.

Source: amazon-inspector (568a31285f414d8125b5749bc8e070157ffd403ce46e46da637cc1452f99d19f)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.