OpenSSF/OSV advisory MAL-2026-17206 confirms this npm version as malicious. The package's postinstall script send_data.js runs automatically on npm install. It reads C:\temp\test.txt from the installer's filesystem and POSTs the contents over plain HTTP to a hardcoded remote endpoint at 35.178.197.251:8080. Package metadata ("Simplified test", author "Purple", UNLICENSED) is consistent with a PoC exfiltration harness rather than a legitimate library.
This report applies to kalasnik-npm-simple-test@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.