-= Per source details. Do not edit below this line.=-
The package ships install-report.js as a preinstall lifecycle script that unconditionally runs on npm install. The script reads os.hostname() and the current working directory basename and transmits them via https.get to a hardcoded third-party collector at https://webhook.site/93b065ab-227f-4253-b940-361d00e9b870/, appending the host identifiers as the URL path. The destination is an anonymous request-inspection endpoint unrelated to any declared package purpose, and the beacon fires silently on every installation without opt-in.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-017686",
"import_time": "2026-08-13T21:20:57.649262244Z",
"modified_time": "2026-08-13T21:08:42Z",
"sha256": "820c7f4f32895ef501e6926f624897cf41b5f868bc21c60852cbfc101b4cd5ba",
"source": "amazon-inspector",
"versions": [
"99.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "install-report.js",
"sha256": "d6d5d7835070f0bac8a27aad788c19a99a97583aefdea9fdff198b8e5cbfe32f",
"tlsh": "1bf0e1be43f460392ee2c1f0b9175ceae10ad519b25056c0d69922b14746cb50cb75f5"
}
],
"package_integrity": [
{
"filename": "core-99.0.0.tgz",
"hashes": {
"sha1": "628ddf642c04c92da955aa5c99fd25d793ec1ee8",
"sha512_sri": "sha512-6KzMKHHMSEs8OMTrZHtAhFfhPDsvNEzoqZbbNqG1JQevO9Sjfdacaj64cmxfu4anTWqeUXlJavO445tIVcYitg=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@khaznatech/core/MAL-2026-13974.json"