Investigate malicious npm packages reported through OSV and public advisories. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 11 Oct 2026, 16:27 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms test8999-auth@1.0.1 as malicious (MAL-2026-16286): Malicious code in test8999-auth (npm)
OpenSSF Malicious Packages via OSV confirms test899-auth@1.0.1 as malicious (MAL-2026-16285): Malicious code in test899-auth (npm)
The only shipped behavior is an automatic postinstall that reads /tmp/flag.txt and sends it to an attacker-controlled ngrok URL. That is unconsented install-time data theft, not a develop...
The published main entrypoint is a default-on harvester that sends cookies and scraped application flags to a hardcoded webhook.site URL. That is concrete exfiltration, so the package is...