Logo
npm

@inpeek/odata-angular@99.99.102

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC

Malicious

OSV ID

MAL-2026-17543

Ecosystem

npm

Summary

@inpeek/odata-angular@99.99.102 is a dependency-confusion squat on the private @inpeek scope, published to the public npm registry at an inflated version (99.99.102) to win resolution against an internal package of the same name. package.json declares scripts.postinstall as 'node./ping.js'; ping.js issues an HTTPS GET to the third-party collector https://db1b65hgnouukn3qov9gta83zgkdao9dy.oast.me/ carrying os.hostname(), os.platform(), process.version, and the package name as query parameters. index.js throws on require, so the package has no legitimate library function; the only install-time effect is the beacon to the external OAST domain. Any CI job or developer workstation whose resolver picks @inpeek/* from the public registry executes the beacon on npm install and leaks host identifiers to an attacker-controlled destination, regardless of a 'bug bounty research' framing in the description.

Source: amazon-inspector (914508dbfa95a3d2cef5aef321a656215797f477c161a8c234e76256db6cac65)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.