OpenSSF/OSV advisory MAL-2026-14251 confirms this npm version as malicious. The package's postinstall lifecycle script collects installer host identifiers (hostname, platform, architecture, Node version, package/lifecycle name, timestamp) and POSTs them as JSON to the hardcoded endpoint https://wxc97jnc.instances.poc.jchunt.top/ngsw-config on npm install, with no consent, documentation, or opt-out...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in ngsw-config (npm)
Details
The package's postinstall lifecycle script collects installer host identifiers (hostname, platform, architecture, Node version, package/lifecycle name, timestamp) and POSTs them as JSON to the hardcoded endpoint https://wxc97jnc.instances.poc.jchunt.top/ngsw-config on npm install, with no consent, documentation, or opt-out. The package name shadows Angular's legitimate ngsw-config tooling, matching a dependency-confusion canary pattern in which internal build systems that misresolve the name automatically report identifying metadata to the operator of the poc.jchunt.top host.
Decision reason
OpenSSF Malicious Packages via OSV confirms ngsw-config@1.0.0 as malicious (MAL-2026-14251): Malicious code in ngsw-config (npm)