OpenSSF/OSV advisory MAL-2026-13453 confirms this npm version as malicious. On `npm install`, the package's postinstall hook runs `node ping.js`, which reads the installer's hostname via `require('os').hostname()` and POSTs it, along with a timestamp and the package name/version, to the hardcoded bare-IP endpoint http://134.119.222.10:9009/canary over plain HTTP. Errors and timeouts are silently swallowed. The version number (99.0.0) and beacon shape are consistent with a...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage ships compressed or archive-like blobs.
pilgrimage-portal-client-99.0.0.tgzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
pilgrimage-portal-client-99.0.0.tgzView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage ships compressed or archive-like blobs.
pilgrimage-portal-client-99.0.0.tgzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
pilgrimage-portal-client-99.0.0.tgzView on unpkg