npm

@hzero-front-ui/cfg @99.99.99

Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 3:31 AM UTC

Malicious

OSV ID

MAL-2026-13968

Ecosystem

npm

Summary

package.json declares preinstall and install lifecycle scripts that, on npm install, collect whoami, hostname, current working directory, and npm_package_name, base64-encode the concatenation, and transmit it to subdomains of callback.m0chan.co.uk via both an HTTPS GET (curl to https://<sub>.callback.m0chan.co.uk/<b64>) and a DNS lookup (nslookup against <pkgdns>.<sub>.callback.m0chan.co.uk). The 99.99.99 version and scoped name pattern are consistent with a dependency-confusion beacon targeting an internal @hzero-front-ui scope.

Source: amazon-inspector (d280060b3d704c67c4a2cc853fde425220e6a3606f71269daa8a9b3e74052f6d)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.