OpenSSF/OSV advisory MAL-2024-2355 confirms this npm version as malicious. faceplate-docs@99.9.10 runs index.js from a postinstall hook that collects the installer's OS username, current working directory, hostname, and local IPv4 address and POSTs them as JSON to a hardcoded anonymous collector at https://webhook.site/f9bff304-3053-4d54-be05-86537267514a. The beacon fires automatically on `npm install` without any user interaction. The package name plus implausibly high version (99.9.10)...
This report applies to faceplate-docs@1.0.0.
1.0.0, 99.9.10, 99.9.9
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.