@wbnr/frontend-shared @99.0.1
Vulnerability report · Last retrieved from osv.dev August 7, 2026 at 2:10 AM UTC
OSV ID
MAL-2026-13436
Ecosystem
npm
Summary
The package declares a preinstall lifecycle script (preinstall.js) that automatically runs on npm install. The script reads the installer's OS username (from process.env USER/USERNAME) and hostname (os.hostname()), embeds them into a subdomain of a hardcoded 4otph6fase1x2won0hrfzul2wt2qqge5.oastify.com callback host, and transmits them via both a DNS lookup and an HTTPS GET to that host at path /depconf/. The behavior is consistent with a dependency-confusion probe using Burp Collaborator (oastify.com) infrastructure; installer identifiers (username, internal hostname, timestamp, package name) are disclosed to a third-party callback domain on every install.
Source: amazon-inspector (6208a0da32b8b7ae795d85ecbf95788b876729db08b0a595ad24f05a02dbbdbe)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.