OpenSSF/OSV advisory MAL-2026-13484 confirms this npm version as malicious. Package advertises itself as a 2048-style grid game statistics utility, but its declared postinstall hook (`node install-cb.js`) executes on `npm install` and performs behavior unrelated to that purpose. The postinstall shells out via execSync to run `uname -a` and `id`, reads `/proc/1/cgroup` and `/proc/mounts`, inspects Linux capabilities, checks for `/var/run/docker.sock`, and reads the Kubernetes service-account...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
install-cb.jsView on unpkg · L3This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
install-cb.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
install-cb.jsView on unpkg · L3This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
install-cb.jsView on unpkg