OpenSSF/OSV advisory MAL-2026-14067 confirms this npm version as malicious. upload-to-gcp@3.2.1 runs a postinstall lifecycle script on npm install that collects host identifiers (os.hostname(), process.platform, process.arch, Node version, package name, npm lifecycle event) and POSTs them to a hardcoded remote endpoint at https://z5owtt3g.instances.poc.jchunt.top/upload-to-gcp...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource appears to send environment or credential material to an external endpoint.
postinstall.jsA package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
postinstall.jsView on unpkg · L2A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
postinstall.jsView on unpkg · L2Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource appears to send environment or credential material to an external endpoint.
postinstall.jsView on unpkg · L2A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
postinstall.jsView on unpkg · L2A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
postinstall.jsView on unpkg · L2