Logo
npm

@inpeek/odata@99.99.102

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC

Malicious

OSV ID

MAL-2026-17542

Ecosystem

npm

Summary

@inpeek/odata@99.99.100 is a dependency-confusion placeholder published to the public npm registry on the unregistered @inpeek scope with an inflated version (99.99.100) designed to outrank any internal release of the same name. The package.json declares a postinstall lifecycle hook that executes ping.js on npm install. ping.js performs an unconditional HTTPS GET to the hardcoded collector URL https://webhook.site/bec9d4b2-8f49-451e-84be-2681cb91ebf2, passing the installer's hostname (os.hostname()), platform (os.platform()), and Node.js version (process.version) as query parameters. index.js throws on require, so any accidental consumer breaks loudly after the postinstall beacon has already fired. The package self-labels as a bug-bounty research placeholder, but the install-time dataflow — automatic transmission of installer host identifiers to a third-party collector the installer did not opt into — is the dependency-confusion exploitation shape and reaches any installer whose tooling resolves @inpeek/* from the public registry.

Source: amazon-inspector (dad085b4b3e089d6a6d4e6812c66a8b45f10d40bc4ab39ea7bd0ce850d17ed4b)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.