Hostile 100% javascript Download

requestor-util 99.9.1

preinstall exfiltrates host identity via OOB

Hollow inflated package uses confusion staging dependencyPackage uses dependency-confusion staging URL
SHA-2562cdf9b06e77a003bf9a186464d614bef7a08d38c6f4313969f9577653264447f

Also flagged by osv (MAL-2026-10965: Malicious code in requestor-util (npm)) +3 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.