OpenSSF/OSV advisory MAL-2026-16316 confirms this npm version as malicious. Package test1sdsd2@99.99.99 declares preinstall and postinstall hooks in package.json that execute index.js on `npm install`. index.js performs an HTTP GET to the hardcoded bare IP http://128.199.122.145/?test1sdsd2, embedding the package name in the query string, which confirms code execution on the installer's machine and leaks install-signal (package name, implicit source IP, timing) to an attacker-controlled...
This report applies to test1sdsd2@99.99.99.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.