Logo
npm

@s4yhiitestpoc/scan-https-d@1.0.0

Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 3:53 PM UTC

Malicious

OSV ID

MAL-2026-17766

Ecosystem

npm

Summary

On npm install, postinstall.js collects installer host identity — os.hostname(), os.userInfo().username, home directory, cwd, non-internal network interface addresses, DNS servers, and platform/arch/release — and POSTs it as JSON over HTTPS to the hardcoded endpoint https://collector.oob.s4yhii.com/_npm-poc/beacon, with a secondary DNS lookup against *.oob.s4yhii.com as an out-of-band execution signal. The package's scope (@s4yhiitestpoc/*) and metadata self-describe this as a dependency-confusion proof-of-concept targeting internal namespaces that resolve to the public registry; the self-labeling does not change the fact that installer host identifiers leave the installer's machine on install to a hardcoded third-party domain the installer did not opt into.

Source: amazon-inspector (1a1dd63de3f5e380c573cd6bcf885c9d0c7a5c503959dfde1a6c8b963a6ddaea)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.