v0-utils 999.999.999
Exfiltrates host data via preinstall
JavaScript accesses hostname near an OOB endpoint and HTTP requestSecurity research claim paired with exfiltration endpoint
SHA-2569f1d0c1a575f700ec3c0808e07d87716d7c481637b3487ee9fe25e8f1b8a02d5
Also flagged by osv (MAL-2025-48090: Malicious code in v0-utils (npm)) +2 more.