OpenSSF/OSV advisory MAL-2026-16290 confirms this npm version as malicious. The package's `install` lifecycle script runs `node index.js`, which loads `lib/core.js`. On install, that module collects `os.userInfo().username`, `os.hostname()`, and the basename of the current working directory, then issues a `dns.resolve4` for a subdomain composed of those values under the hardcoded external domain `oob.algamil7x.xyz`...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource appears to send environment or credential material through DNS lookups.
lib/core.jsView on unpkgThis report applies to @insiderintelligence/googleadmanager@9.9.10.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource appears to send environment or credential material through DNS lookups.
lib/core.jsView on unpkg