Logo
npm

whs4_eud@1.0.1

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 7:42 AM UTC

Malicious

OSV ID

MAL-2026-11071

Ecosystem

npm

Summary

whs4_eud@1.0.1 declares a postinstall lifecycle script (node index.js) that fires unconditionally on npm install. On execution, index.js POSTs installer-side host information — the absolute path of the install location (which embeds the user's home directory), Node.js version, and platform/architecture — to a hardcoded Discord webhook under discord.com/api/webhooks/1530599209269465319/. The webhook URL is assembled by concatenating two string literals at runtime rather than appearing as a single literal, a light obfuscation of the exfiltration destination. The package name and layout are consistent with a dependency-confusion / typosquat beacon whose only functional behavior is to notify the author when an install occurs and to disclose where.

Source: amazon-inspector (6be47b29c887fd54b5cffc8789278f3ea7987b12d618e89c540e5670edea12b5)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.