OpenSSF/OSV advisory MAL-2026-16414 confirms this npm version as malicious. The package's `scripts.install` runs `node index.js`, which loads a runtime bootstrap that reaches a 'telemetry probe' helper. The helper dynamically loads Node built-ins `os`, `dns`, and `process` via `module.constructor._load` using names reconstructed from `String.fromCharCode` char-code arrays, then reads `os.userInfo().username`, `os.hostname()`, and the basename of `process.cwd()`, concatenates them with a...
This report applies to @tvg-mar/storyblok-bridge@9.9.10.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.