OpenSSF/OSV advisory MAL-2026-17316 confirms this npm version as malicious. package.json declares a postinstall lifecycle hook `wscript.exe 4444.vbs` that runs Windows Script Host against a `.vbs` file on `npm install`. The referenced `4444.vbs` is not shipped in the tarball, so the hook either fails or (if the file is dropped by another mechanism or provided out-of-band) executes attacker-authored VBScript on the installer's machine at install time...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThis report applies to booking-eligibility@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg