bcc-design-icons @9999.0.0
Vulnerability report · Last retrieved from osv.dev August 18, 2026 at 9:44 AM UTC
OSV ID
MAL-2026-14119
Ecosystem
npm
Summary
bcc-design-icons@9999.0.0 declares a postinstall script node./notify.js that runs automatically on npm install . The script performs an HTTP GET to the hardcoded bare-IP endpoint http://91.201.215.48:8000/npm-poc-bcc with query parameters containing os.hostname() and the package name. The 9999.0.0 version, absence of any icon-library functionality expected from the package name, and callback-to-bare-IP shape match a dependency-confusion attack that identifies internal/private installers to the operator. Hostname is host-identifying data exfiltrated to an attacker-controlled destination without any installer opt-in.
Source: amazon-inspector (8f25ef58a44d6da495f8f9cd06686303901d391069000f5a10d09694b68241e2)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.