Logo
npm

cre-setup@1.0.0

Vulnerability report · Last retrieved from osv.dev September 6, 2026 at 6:01 AM UTC

Malicious

OSV ID

MAL-2026-15591

Ecosystem

npm

Summary

bin/cli.js collects the current user (whoami/os.userInfo()), os.hostname(), and os.platform() and POSTs them, along with URL query parameters carrying the same values, to the hardcoded endpoint https://oobme.kunalsharma0553.workers.dev/r/7bq6fz3l15r9 on invocation. There is no configuration option, no opt-in, and no documented purpose that requires transmitting installer/runner identity off-host. The destination is an out-of-band callback URL under an individual-controlled Cloudflare Workers subdomain, characteristic of dependency-confusion / npx reconnaissance beacons.

Source: amazon-inspector (fcc14c964a76dde24165930e971dac9a2a9f36ecae68d596c7bf920cac8e1c29)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.