OpenSSF/OSV advisory MAL-2026-16050 confirms this npm version as malicious. @aspect-adv-ui/consent-manager 2.4.1 declares a postinstall hook (`node setup.js`) that fires automatically on every `npm install`. setup.js issues an HTTPS GET to a hardcoded webhook.site inspection endpoint (https://webhook.site/kapper), sending install-event metadata (source IP, TLS/user-agent fingerprint) to an author-controlled third-party collector...
This report applies to @aspect-adv-ui/consent-manager@2.4.0.
2.4.0, 2.4.1
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.