OpenSSF/OSV advisory MAL-2026-15536 confirms this npm version as malicious. package.json declares a dependency whose key equals the package's own name (`ir-annuities-client-authentication-module`) and whose value is a plain HTTPS URL to a non-registry host (`https://repo.securityctrl.com/ir-annuities-client-authentication-module`) instead of a semver range...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in ir-annuities-client-authentication-module (npm)
Details
package.json declares a dependency whose key equals the package's own name (`ir-annuities-client-authentication-module`) and whose value is a plain HTTPS URL to a non-registry host (`https://repo.securityctrl.com/ir-annuities-client-authentication-module`) instead of a semver range. On `npm install`, npm fetches whatever bytes that URL currently returns and installs them as this dependency, with no version pin, no integrity hash, and no registry provenance; any lifecycle scripts contained in the fetched artifact execute on the installer. The dependency key matching the package's own name creates a dependency-confusion shape that can win resolution against an internal package of the same name. The shipped index.js is an inert stub, so the manifest itself is the delivery mechanism — the absence of local scripts does not prevent the fetch or its lifecycle execution.
Decision reason
OpenSSF Malicious Packages via OSV confirms ir-annuities-client-authentication-module@30.0.0 as malicious (MAL-2026-15536): Malicious code in ir-annuities-client-authentication-module (npm)