@coopeuch/common@1.999.999
Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 3:53 PM UTC
OSV ID
MAL-2026-17760
Ecosystem
npm
Summary
@coopeuch/common@1.999.999 publishes to the public npm registry under a scope the publisher does not own, using an inflated version (1.999.999) consistent with the dependency-confusion technique that outranks internal-registry versions. The package's declared postinstall script (postinstall.js) runs automatically on npm install and collects installer-side host and network data — hostname, username, uid/gid, home directory, non-internal network interface addresses with MAC/CIDR, DNS resolver addresses, reverse-DNS internal FQDN, container markers, CI environment-variable presence, npm_config_registry, and the consuming project's package name/version/declared range — then POSTs it as JSON to the hardcoded author-controlled endpoint https://collector.oob.s4yhii.com/_npm-poc/beacon. A secondary DNS beacon is emitted via dns.lookup to a subdomain of oob.s4yhii.com. Any build that resolves @coopeuch/common from the public registry (including internal builds referencing the @coopeuch scope) will auto-exfiltrate internal hostnames, MAC addresses, usernames, internal registry URLs, and project identity to a third-party collector at install time. The package's README self-labels this as a coordinated-disclosure proof of concept; the harvesting and off-host upload nonetheless occur without installer opt-in.
Source: amazon-inspector (887c41c0805d7d223c499e702796cf46727b0be152b7c8a65607907afb3b5d59)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.