OpenSSF/OSV advisory MAL-2026-15941 confirms this npm version as malicious. Package name resembles an internal-scoped name and uses an implausibly high version (9999.0.0) consistent with dependency-confusion targeting. The preinstall.js lifecycle script runs automatically on `npm install` and collects installer identifiers (os.hostname, os.userInfo().username, cwd, __dirname, platform/os.release, node version, npm user-agent, resolved package name and version) and transmits them through...
This report applies to ocfe-tv-subscription-center-web@9999.0.0.
0.0.1, 9999.0.0
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.