OpenSSF/OSV advisory MAL-2026-16175 confirms this npm version as malicious. package.json declares a preinstall script that runs wget against http://169.58.142.14:8080/ with query parameters populated by shell command substitution of whoami, ls, and hostname. On npm install this automatically transmits the installer's username, current-directory listing, and hostname to a hardcoded bare-IP HTTP endpoint unrelated to any legitimate publisher infrastructure...
This report applies to csa-mfa@1.1.15.
1.1.15, 1.1.16
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.