-= Per source details. Do not edit below this line.=-
The package's postinstall hook runs index.js, which POSTs the installer's absolute filesystem path (via __filename with sendFullPath: true), Node.js version, platform, and architecture to a hardcoded Discord webhook at discord.com/api/webhooks/1530599209269465319/. The same beacon also fires when the module is required, since index.js is the package main. The absolute path typically embeds the local username and home directory, giving the operator of the webhook a host/identity fingerprint of every machine that installs the package. The webhook URL is split across two string literals and concatenated at call time to evade casual string scanning, and the destination is not caller-configurable. The package name and README self-describe as a typo/beacon experiment.
The OpenSSF Package Analysis project identified 'wsh4_edu' @ 1.0.0 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"import_time": "2026-07-27T01:42:44.001805577Z",
"modified_time": "2026-07-25T16:00:59Z",
"sha256": "e68d4c62ae8440581c4400e1cdacb7877912eb23610e273432d18cea61574785",
"source": "ossf-package-analysis",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-011286",
"import_time": "2026-08-04T22:30:09.012734888Z",
"modified_time": "2026-08-04T21:59:29Z",
"sha256": "0757eee7b6324baca2e2b28261c7ff072c60d578c827a14c1fa54f690b1cd53a",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "1ba5b8478d28998c0247fc7f00c236e29a12dcec1fb5dc5ca507933918306c4b",
"tlsh": "9861438a96f022210b73f3d4614bc12bbb2985132a4ecd45f64c57b41fce67dd4e56e8"
}
],
"package_integrity": [
{
"filename": "wsh4_edu-1.0.0.tgz",
"hashes": {
"sha1": "2a2859885ffde7e7def6bbd59f776f9549438003",
"sha512_sri": "sha512-g+ocCAOI14yj2nGBbFAWBAkQIK+0jfZ67DTSe62cNlMkofj1hcjfSDEXruu0yUNKexIk/pSsT67ivafbmjwPSg=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/wsh4_edu/MAL-2026-11072.json"