@heartlandone-private/fontawesome-pro @6.3.6
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC
OSV ID
MAL-2026-11093
Ecosystem
npm
Summary
Package published to public npm under a private-looking scope (@heartlandone-private/fontawesome-pro) with a postinstall script that runs index.js. On install, index.js issues an HTTPS request to a hardcoded Burp Collaborator subdomain at r7z7t23a9hkqmzl06zndpczfh6nxbszh.oastify.com/dependency-confusion-fontawesome with a custom User-Agent identifying the package. Any developer or build system whose registry configuration resolves this scope from public npm will, at install time, disclose to the operator of the Collaborator host that resolution occurred, along with the installer's outbound IP and DNS resolver. The self-label 'authorized dependency-confusion validation' does not change the mechanism: the destination is not controlled by the installer, the beacon fires without consent on npm install, and the package's only functional behavior is this outbound signal.
Source: amazon-inspector (d682e0698802296817059bcf0421cc3c7e92ad2e173d58e57614596607bcbe43)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.