zeal-utils@0.0.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 10:33 AM UTC
OSV ID
MAL-2026-16542
Ecosystem
npm
Summary
canary.js in zeal-utils@0.0.0 collects host reconnaissance data (os.hostname(), os.userInfo(), process.platform, cwd, node version) and POSTs it to the hardcoded external endpoint https://npm-canary.aveliscare.com. The destination is not a package registry or documented vendor endpoint and is unrelated to any legitimate utility functionality implied by the package name. The package name and near-empty version (0.0.0) combined with a single script that beacons system identification to an author-controlled host is consistent with a dependency-confusion or canary-token style beacon that identifies internal build environments where the package resolves.
Source: amazon-inspector (f7a4b9b4fcb0a48aa3602fc7bc865eff738f8ab42a4c9e56ea31e70b0b6b826f)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.