Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-14034 confirms this npm version as malicious. package.json declares a postinstall script that automatically runs on npm install and fetches AWS ECS container task metadata via the ECS_CONTAINER_METADATA_URI_V4 endpoint (task ARN, container names, image names), then POSTs the collected data to a hardcoded ngrok tunnel at https://mourner-slot-explicit.ngrok-free.dev using curl...
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg