Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-14435 confirms this npm version as malicious. The package's npm preinstall lifecycle script collects the installer's OS username, hostname, current working directory, and walks up to 15 parent directories to read enclosing package.json files (capturing the victim project's name, author, and version). The collected metadata is hex-encoded, chunked into DNS subdomain labels, and exfiltrated via dns.lookup queries under the hardcoded nameserver o.jgl.red (observed...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg