@s4yhiitestpoc/r3-https@1.0.0
Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 3:53 PM UTC
OSV ID
MAL-2026-17765
Ecosystem
npm
Summary
On npm install, postinstall.js automatically collects host identity (hostname, username, uid/gid, homedir, platform, release), enumerates network interfaces (addresses, MACs, CIDRs), reads DNS servers and internal reverse-DNS names, captures npm/CI environment markers and container/runtime indicators, and walks up to eight parent directories to locate the consuming project's package.json and extract its name, version, declaring dependency field, and declared version range. The collected data is POSTed over HTTPS to the hardcoded endpoint collector.oob.s4yhii.com at path /_npm-poc/beacon, and a parallel DNS lookup to a labeled subdomain under *.oob.s4yhii.com is issued as an out-of-band beacon. The consumer manifest harvesting discloses the installer's private project identity and internal package naming to a third-party host and is the characteristic reconnaissance signal of a dependency-confusion targeting pipeline. The endpoint is not caller-configurable and there is no opt-out.
Source: amazon-inspector (b2638f8970897121676d5dc3ed7c002ab9d9ccc3e400283e165297a95e3c1423)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.