Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-15921 confirms this npm version as malicious. package.json declares a preinstall hook that runs index.js on `npm install`. The script reads the installer's hostname and OS username, embeds them together with a timestamp into a DNS subdomain of the form `poc-<hostname>-<user>-<timestamp>.iv6mfybhp42k33ysmzi73de5w.canarytokens.com`, and issues a DNS resolution for that name, causing the installer's host and user identifiers to be transmitted to a third-party...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg