Harmless OWASP IoT supply-chain static-analysis training fixture
OpenSSF/OSV advisory MAL-2026-17652 confirms this npm version as malicious. On `npm install`, the package's declared postinstall script executes index.js, which collects a host fingerprint (hostname, username, home directory, cwd, platform/arch/OS release, CPU model, memory, network interfaces including MAC/OUI, process info) and enumerates process.env for variable names matching TOKEN|SECRET|KEY|PASS|AWS_|GCP_|AZURE_|SSH|GIT|NPM|DOCKER...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThis report applies to @ziedzzz/demo-canary@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L8