OpenSSF/OSV advisory MAL-2026-16116 confirms this npm version as malicious. The package's preinstall lifecycle script (preinstall.js) reads the installer's OS hostname, username, and current working directory via os.hostname(), os.userInfo().username, and process.cwd(), encodes them into a URL path, and issues an HTTP GET to a hardcoded bare-IP endpoint at http://209.126.81.147/etoro-depconf-.../npm/<hostname>/<username>/<cwd>...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThis report applies to etoro-builders@999.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg