OpenSSF/OSV advisory MAL-2026-16243 confirms this npm version as malicious.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
callback.jsView on unpkg · L11Source appears to send environment or credential material to an external endpoint.
callback.jsView on unpkg · L11Source appears to send environment or credential material through DNS lookups.
callback.jsView on unpkg · L11A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
callback.jsView on unpkg · L11Manifest-reachable source sends caller or host-sensitive data to a package-embedded authenticated webhook.
callback.jsView on unpkgA manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
callback.jsView on unpkg · L11This report applies to idx_form_script@999.0.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
callback.jsView on unpkg · L11Source appears to send environment or credential material to an external endpoint.
callback.jsView on unpkg · L11Source appears to send environment or credential material through DNS lookups.
callback.jsView on unpkg · L11A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
callback.jsView on unpkg · L11Manifest-reachable source sends caller or host-sensitive data to a package-embedded authenticated webhook.
callback.jsView on unpkgA manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
callback.jsView on unpkg · L11