Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-14036 confirms this npm version as malicious. The package.json postinstall script auto-executes on npm install. It queries the ECS container metadata endpoint (ECS_CONTAINER_METADATA_URI_V4/task) to collect the Task ARN, container image list, and log group/stream configuration, then enumerates process.env for keys matching /owner|team|user|created|author|maintainer|contact/i, and pipes the resulting report via `curl -X POST --data-binary @-` to the hardcoded...
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg