SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Package is malware. Exfiltrates data via pre/postinstall scripts, and has a suspicious main entrypoint targeting MongoDB configurations.

Verification Record

The package is marked as malware by OSV: MAL-2026-1260 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple strong indicators of malicious behavior. The package.json file contains suspicious preinstall and postinstall scripts that use curl to send sensitive information (username, hostname, current directory, timestamp) to a remote server. This data exfiltration is a significant red flag. Additionally, the main field pointing to .mongorc.js is highly unusual and suggests an attempt to inject malicious code into MongoDB environments. The combination of these factors, including the use of requestrepo.com, which is often associated with malicious activity, leads to the conclusion that this package is likely malware.

webmd-url@77.7.7Malicious
Verified
Analysed at: 3/4/26, 6:47 PM
Source: https://registry.npmjs.org/webmd-url/-/webmd-url-77.7.7.tgz
SHA256: d8a8762a73b04dabdeed9d1c31a66cc09832678943dd06420b819a652c3fe932
Confidence: High