@finxsecdemo/utils @1.0.3
Vulnerability report · Last retrieved from osv.dev August 15, 2026 at 10:37 PM UTC
OSV ID
MAL-2026-11170
Ecosystem
npm
Summary
The postinstall.js lifecycle script unconditionally issues an HTTPS GET and a DNS resolution against a hardcoded interact.sh/OAST subdomain (llhvrrffsffmousfvteqie2heq3c7rl55.oast.fun) on every install, reading os.hostname(), os.userInfo(), and process.env in the surrounding code. The beacon fires on npm install and reports the installer's source IP and DNS resolver IP to whoever owns the OAST token, giving them an enumeration list of hosts on which the package landed. The package's own main returns a formatCurrency string containing '[DEPENDENCY-CONFUSION-POC: this ran from the PUBLIC npm registry, not @finxsecdemo private packages]', which corrupts any consumer that displays formatted currency. Console framing as a 'dependency confusion PoC' is author-controlled labeling; the network callback and output corruption occur regardless.
Source: amazon-inspector (be118b4cf0acab2c331cc37f68a19bdbdf2ac8423ef984a1cac5c9f4d21c1e7e)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.