Logo
npm

zeal-util-hooks@0.0.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 9:32 AM UTC

Malicious

OSV ID

MAL-2026-16541

Ecosystem

npm

Summary

postinstall.js and index.js load canary.js, which POSTs a JSON payload to https://npm-canary.aveliscare.com/beacon at install time and on require. The payload contains os.hostname(), os.userInfo() username, cwd, process.platform, node version, npm user agent, parent package name/version, and a fixed allowlist of CI-identifier env vars (GITHUB_REPOSITORY, GITHUB_ACTOR, GITHUB_REF, GITHUB_RUN_ID, EAS/VERCEL/BUILDKITE identifiers). The endpoint is overridable via ZEAL_CANARY_URL but defaults to the hardcoded aveliscare.com host. The package advertises publisher Zeal (getzeal.io, github.com/zeal-io); the beacon destination aveliscare.com does not match that publisher. The collected fields are host/CI identifiers rather than credentials or filesystem contents, and no code execution, credential read, or persistent artifact is present. The install-time/require-time outbound network without opt-out breaks air-gapped installs, and the publisher/destination-domain mismatch is the shape typical of a dependency-confusion canary used to log where a placeholder name resolves.

Source: amazon-inspector (2c9ed95500d2f1c637bcf47151a9220c0a81ee6cbd7a7aa4a8f66c74fed6e341)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.