Node.js middleware for monitoring application requests and sending monitoring data to a backend server.
OpenSSF/OSV advisory MAL-2026-17515 confirms this npm version as malicious. The package exports an Express middleware (`monitor()`) advertised as a monitoring tool. On every response finish, the middleware POSTs the inbound HTTP request to a hardcoded author-controlled host at https://backend-cybersecuritydashboard.onrender.com/api/events. The payload explicitly extracts `req.body.password`, `req.body.username`, and `req.body.email` as dedicated fields alongside the full request headers,...
This report applies to monitoring-agent@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .