OpenSSF/OSV advisory MAL-2026-16437 confirms this npm version as malicious. eslint-plugin-i18n-shreddit@99.9.9 ships no ESLint plugin code; the tarball's only function is a postinstall hook (scripts.postinstall = 'node index.js') that runs automatically on `npm install`. index.js collects installer-side reconnaissance — os.userInfo().username, process.cwd(), os.hostname(), and the local IPv4 address — and POSTs the values as JSON to a hardcoded anonymous collector at...
This report applies to eslint-plugin-i18n-shreddit@99.9.9.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.