OpenSSF/OSV advisory MAL-2026-16113 confirms this npm version as malicious. The preinstall lifecycle script in etoro-api@999.0.0 (preinstall.js) auto-executes on npm install and performs an HTTP GET to a hardcoded bare-IP endpoint at http://209.126.81.147/etoro-depconf-poce346552f776f/npm/<host>/<user>/<cwd>, embedding the installer's hostname (os.hostname()), OS username (os.userInfo().username), and current working directory (process.cwd()) as URL path components...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThis report applies to etoro-api@999.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg