MAL-2025-47594
Malicious code in paypal-postman-lib (npm)
Details
The package communicates with a domain associated with malicious activity.
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (c2b733a611e3d27e56f4c6ee549bbcf3d88a1c823512c13797440c4c13f2712c) The package's index.js imports os, fs, and https at the top level and reads os.hostname() and os.userInfo() before sending the collected host identity over an outbound HTTPS request. The package name impersonates PayPal/Postman branding while shipping no legitimate library functionality, and the only observable behavior is collection and transmission of installer host data. Installing or requiring this package causes the installer's hostname and OS user identity to be sent to a third-party endpoint.
Are you affected?
Enter the version of the package you're using.
Affected packages
2.0.9 No fixed version published yet for paypal-postman-lib (npm). Pin to a known-safe version or switch to an alternative.