Hostile 100% javascript Download

commonweb-rewards 99.9.1

preinstall exfiltrates host data via OOB

Hollow inflated package uses confusion staging dependencyPackage uses dependency-confusion staging URL
SHA-2562cded25d94a03b828488da221c43c5f9b401bacc0245dec33375a846ff47326e

Also flagged by osv (MAL-2026-10968: Malicious code in commonweb-rewards (npm)) +3 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.