OpenSSF/OSV advisory MAL-2026-17561 confirms this npm version as malicious. index.js, the package's main entry, runs at require() time with no user interaction. On load it spawns OS-native calculator processes via child_process.exec ('calc.exe' on Windows, 'open -a Calculator' on macOS, 'gnome-calculator' on Linux) to demonstrate arbitrary code execution; writes a marker file to the user's Desktop (INSOMNIA_RCE_PROOF.txt); and serializes the full process.env object with JSON.stringify and...
This report applies to insomnia-plugin-api-lint-helper@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.