-= Per source details. Do not edit below this line.=-
The package's postinstall hook runs index.js, which collects the installer's OS username, current working directory, hostname, and local IPv4 address and POSTs them as JSON to a hardcoded webhook.site collector URL (https://webhook.site/f9bff304-3053-4d54-be05-86537267514a) on npm install. The package name is a random keyboard-mash string with no documented purpose, and the only on-install behavior is the outbound beacon to an anonymous ephemeral webhook endpoint controlled by whoever created the webhook.site token.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020322",
"import_time": "2026-09-23T01:50:18.729889547Z",
"modified_time": "2026-09-23T01:36:34Z",
"sha256": "4845639223c486cf2d33751ad950cea4c7f70401877929d25c36e7d07655d820",
"source": "amazon-inspector",
"versions": [
"99.9.9"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "a07fd09c2dccd9dcbe917ab7def77cfff55b6f6ea89ab4d6422de1542d12ca1f",
"tlsh": "ac11cee58cab10100eb177b14c024805f7225722b51a9781b9bcc19d2fa69a5a271eec"
}
],
"package_integrity": [
{
"filename": "efhthrthrthregerht-99.9.9.tgz",
"hashes": {
"sha1": "f2ddb8db11678f5288f77d5184c22814d04da47a",
"sha512_sri": "sha512-YgCWjWp4Bkx43ryQmiLMWXm+wHfo1sgFGe0bpZQOqhsy427JFg4rTCQrmyDh/yt+su5SLqvWln4IXAeds5AsIw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/efhthrthrthregerht/MAL-2026-16436.json"