Logo
npm

@coopeuch/button@1.999.999

Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 3:53 PM UTC

Malicious

OSV ID

MAL-2026-17759

Ecosystem

npm

Summary

The package's postinstall lifecycle script (postinstall.js) runs automatically on npm install and harvests installer host identifiers — hostname, username, uid/gid, home directory, non-internal network interfaces with MAC addresses and CIDRs, configured DNS servers, reverse-DNS internal FQDN, CPU/memory, the consumer package name/version/path, CI markers, npm_config_* values, and container runtime indicators — then POSTs the JSON report over HTTPS to the hardcoded host collector.oob.s4yhii.com at /_npm-poc/beacon and issues a DNS lookup for a label-prefixed subdomain of oob.s4yhii.com as an out-of-band beacon. The destination is not the installer's own infrastructure and is not caller-configurable. The @coopeuch scope combined with the 1.999.999 version has the shape of dependency-confusion targeting of a specific organization's internal namespace, in which npm install resolves this public package in place of an intended internal one and emits the fingerprint to the author's collector.

Source: amazon-inspector (ee1a3bb0818d46a9c83659ed32f8ab209477970658d5f6f8241a12c96d137c98)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.