@united-airlines-org/atmos-design-system @41.0.0
Vulnerability report · Last retrieved from osv.dev August 7, 2026 at 2:10 AM UTC
OSV ID
MAL-2026-13435
Ecosystem
npm
Summary
Package @united-airlines-org/atmos-design-system@41.0.0 ships no library code — only a package.json whose preinstall script runs /usr/bin/curl to https://bxss.boll-sec.de/callb with base64-encoded values of uname -n , ls of the current directory, and whoami as query parameters. This fires automatically on npm install , sending the installer's hostname, working-directory listing, and username to an external, non-first-party host. The scope name resembles an internal United Airlines organization and the package contains no functional code beyond the beacon, matching the dependency-confusion pattern in which resolution of an internal package name pulls in an attacker-published public artifact.
Source: amazon-inspector (5683e7389b9b288024f2c9827c3649d7b291996625265f6365535121fc1f431a)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.