Hostile 100% javascript Download

v0-runtime 999.999.22003

OOB exfiltration via preinstall hook

preinstall hook in sparse package with inflated version metadatapreinstall runs local JS contacting OOB callback
SHA-25621f2063ee6c681a0948b9f016cb16336ed2161e48c0f849cb4fb271f9d1f488f

Also flagged by osv (MAL-2025-48089: Malicious code in v0-runtime (npm)) +2 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.