SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Malware detected: Collects and exfiltrates sensitive data to a suspicious webhook via a preinstall script.

Verification Record

The package is marked as malware by OSV: MAL-2026-1317 with source: ghsa-malware

Details

Note: This report is updated by a verification record

The package is a malware because multiple pieces of evidence point to malicious behavior. The preinstall.js script collects sensitive information like hostname, username, Node.js version, current working directory, NPM environment variables, CI environment variables, and network interface information. This data is then exfiltrated to a suspicious webhook URL (webhook.site). The package.json file executes the preinstall.js script during the preinstall phase, allowing arbitrary code execution. The combination of data exfiltration and arbitrary code execution during installation strongly suggests malicious intent.

@augmentor/experiences@101.0.0Malicious
Verified
Analysed at: 3/6/26, 5:02 PM
Source: https://registry.npmjs.org/@augmentor/experiences/-/experiences-101.0.0.tgz
SHA256: 3f094730efa01c7c7797314806988699a7644439f399f78c1d1ee76466831347
Confidence: High