OSV ID
MAL-2026-11071
Ecosystem
npm
Summary
whs4_eud@1.0.1 declares a postinstall lifecycle script (node index.js) that fires unconditionally on npm install. On execution, index.js POSTs installer-side host information — the absolute path of the install location (which embeds the user's home directory), Node.js version, and platform/architecture — to a hardcoded Discord webhook under discord.com/api/webhooks/1530599209269465319/. The webhook URL is assembled by concatenating two string literals at runtime rather than appearing as a single literal, a light obfuscation of the exfiltration destination. The package name and layout are consistent with a dependency-confusion / typosquat beacon whose only functional behavior is to notify the author when an install occurs and to disclose where.
Source: amazon-inspector (6be47b29c887fd54b5cffc8789278f3ea7987b12d618e89c540e5670edea12b5)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.