THREATPKG
SYNC STALE

Supply-chain threat intelligence

Incident detail

criticalnpm·typosquatting·osv

Malicious code in getd-pantallas-cliente (npm)

getd-pantallas-cliente

Risk score

92

AI summary

Indexed incident for getd-pantallas-cliente (npm).

Description

On npm install, postinstall.js collects os.hostname(), os.userInfo().username, os.platform(), process.cwd(), and CI/build environment variables and sends them as URL query parameters via HTTPS GET to an anonymous webhook.site endpoint (https://webhook.site/18dc4281-d366-438a-9186-76fbcd56ade5). Errors are silently swallowed; there is no opt-in or disclosure. The package's own package.json description self-identifies as a typosquat placeholder for the @getd/* scope, so any installer who mistypes a scoped package name has their machine fingerprinted and shipped to a third-party endpoint outside their control. Regardless of the author's stated 'defensive research' framing, the on-install behavior is unconsented exfiltration of installer-identifying data to an anonymous, ephemeral destination.

Technical details

Affected versions

=0.0.1

Indicators

  • affected version=0.0.175%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents