@s4yhiitestpoc/scan-https-d@1.0.0
Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 3:53 PM UTC
OSV ID
MAL-2026-17766
Ecosystem
npm
Summary
On npm install, postinstall.js collects installer host identity — os.hostname(), os.userInfo().username, home directory, cwd, non-internal network interface addresses, DNS servers, and platform/arch/release — and POSTs it as JSON over HTTPS to the hardcoded endpoint https://collector.oob.s4yhii.com/_npm-poc/beacon, with a secondary DNS lookup against *.oob.s4yhii.com as an out-of-band execution signal. The package's scope (@s4yhiitestpoc/*) and metadata self-describe this as a dependency-confusion proof-of-concept targeting internal namespaces that resolve to the public registry; the self-labeling does not change the fact that installer host identifiers leave the installer's machine on install to a hardcoded third-party domain the installer did not opt into.
Source: amazon-inspector (1a1dd63de3f5e380c573cd6bcf885c9d0c7a5c503959dfde1a6c8b963a6ddaea)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.