OpenSSF/OSV advisory MAL-2026-17307 confirms this npm version as malicious. The package declares scripts.postinstall = 'node index.js'. On install, index.js performs an HTTPS GET to the hardcoded host fabric-npm.gm-service.xyz at path /p and passes the response body to vm.runInContext, executing whatever code the server returns on the installer's machine. The host and path are stored in short obfuscated variables (_h, _p)...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThis report applies to fabric-mod-utils@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg