@selfpentest/bin-confusion@1.0.1
Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC
OSV ID
MAL-2026-17292
Ecosystem
npm
Summary
package.json registers a bin entry named npm pointing at npm.js, deliberately colliding with the core npm CLI. Once this package is installed as a dependency, any npm... invocation in a consuming project's scripts resolves via node_modules/.bin to this shim, executing the shipped code before (or instead of) the real npm. npm.js contains a steal() routine that reads process.env.HOME, process.env.SECRET, and the first 30 bytes of ~/.ssh/known_hosts, concatenates them into a query string, and issues a fetch GET to http://localhost:1337/. The destination is loopback in this build, but the collected data (installer SSH known_hosts contents and environment secrets) is packaged into a functioning exfiltration primitive that fires whenever the shadow npm shim is invoked from the installer's build scripts. The scope name (@selfpentest) and README frame this as a demonstration, but the shipped tarball is a working bin-shadow + credential-read + network-send chain against installers who add it as a dependency.
Source: amazon-inspector (40a68543ca2674f2b90d89dd52516736791b7886d617c694d89dd3135e7499f3)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.