Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-16480 confirms this npm version as malicious. a-onesite@99.9.9 ships an empty index.js and no library functionality. Its package.json declares preinstall, preupdate, and test scripts that all invoke wget against http://eoy34oyrep9j5x8.m.pipedream.net with the installer's username ($(whoami)), current working directory ($(pwd)), and hostname ($(hostname)) as query parameters...
This report applies to a-onesite@99.9.9.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.