Logo
npm

@s4yhiitestpoc/r2-https@1.0.0

Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 3:53 PM UTC

Malicious

OSV ID

MAL-2026-17764

Ecosystem

npm

Summary

On npm install, the package's declared postinstall script (postinstall.js) collects installer host fingerprint data — hostname, username, home directory, platform/arch/OS release, current working directory, install directory, DNS server list, non-internal network interface addresses, Node.js version, and npm_* environment values including npm_config_registry — and POSTs the collected JSON to https://collector.oob.s4yhii.com/_npm-poc/beacon. It additionally performs an out-of-band DNS lookup against a subdomain of oob.s4yhii.com (db03o8lag74hsugsg2j091t8mfcf437h3.oob.s4yhii.com) to confirm execution via DNS exfiltration. The destination is a hardcoded author-controlled domain, the behavior fires automatically at install time without consent, and the exfiltrated data includes npm_config_registry which can disclose an internal/private registry URL. A self-described 'PoC' or 'coordinated disclosure' framing does not change the fact that installer-identifying data and internal registry configuration leave the host to a third-party endpoint.

Source: amazon-inspector (b6042f718b39be380eeda7c31dc46b056e753cb8a39e51897c8106e49b44f4d0)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.