cre-setup@1.0.0
Vulnerability report · Last retrieved from osv.dev September 6, 2026 at 6:01 AM UTC
OSV ID
MAL-2026-15591
Ecosystem
npm
Summary
bin/cli.js collects the current user (whoami/os.userInfo()), os.hostname(), and os.platform() and POSTs them, along with URL query parameters carrying the same values, to the hardcoded endpoint https://oobme.kunalsharma0553.workers.dev/r/7bq6fz3l15r9 on invocation. There is no configuration option, no opt-in, and no documented purpose that requires transmitting installer/runner identity off-host. The destination is an out-of-band callback URL under an individual-controlled Cloudflare Workers subdomain, characteristic of dependency-confusion / npx reconnaissance beacons.
Source: amazon-inspector (fcc14c964a76dde24165930e971dac9a2a9f36ecae68d596c7bf920cac8e1c29)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.