SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Malicious package due to data exfiltration via preinstall, test and preupdate scripts using wget to send user, path, and hostname to a remote server.

Verification Record

The package is marked as malware by OSV: MAL-2026-2633 with source: ghsa-malware

Details

Note: This report is updated by a verification record

The package exhibits multiple strong indicators of malicious behavior. The package.json file contains preinstall, test and preupdate scripts that use wget to exfiltrate sensitive information such as the username, current path, and hostname to a remote server (webhook.site). This is a clear indication of data exfiltration. Furthermore, the project has only one published version, which raises concerns about its maturity and maintenance. These multiple pieces of evidence lead to the conclusion that the package is likely malicious.

markdownlint-rule-link-pattern@8.0.0Malicious
Verified
Analysed at: 4/13/26, 6:13 AM
Source: https://registry.npmjs.org/markdownlint-rule-link-pattern/-/markdownlint-rule-link-pattern-8.0.0.tgz
SHA256: c890bcc1a12755a2642c61caacb6b5d1b371c49ae8a0e6312965a14f1e393bd1
Confidence: High