Hostile 100% javascript Download

v0-utils 999.999.999

Exfiltrates host data via preinstall

JavaScript accesses hostname near an OOB endpoint and HTTP requestSecurity research claim paired with exfiltration endpoint
SHA-2569f1d0c1a575f700ec3c0808e07d87716d7c481637b3487ee9fe25e8f1b8a02d5

Also flagged by osv (MAL-2025-48090: Malicious code in v0-utils (npm)) +2 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.