OpenSSF/OSV advisory MAL-2026-16176 confirms this npm version as malicious. The package's preinstall script (index.js) runs automatically on npm install and collects host identifiers via os.hostname(), os.userInfo(), os.homedir(), and DNS lookups, then JSON-stringifies the entire process.env and POSTs both payloads to a hardcoded external host at https://l2ha5tswnm71286wnjgrngvb4tyejmdpe.i.dr0gas.com/exf. Bulk process.env serialization on developer and CI machines captures whatever secrets...
This report applies to fulfillment-cuprum-auth-widget@3.7.1.
3.7.2, 1.0.0, 3.7.0-rc-37, 3.7.1
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.