dbconnectify @1.0.2
Vulnerability report · Last retrieved from osv.dev August 19, 2026 at 11:52 AM UTC
OSV ID
MAL-2026-10669
Ecosystem
npm
Summary
The package exposes a method queryDBConnect that base64-decodes a hardcoded URL ( HASH_KEY → https://api.jsonbin.io/v3/b/6a609e63f5f4af5e29b05907), performs an HTTP GET against it, reads a string from the response field data.record.cookie , and passes that string to Module._compile(..., 'errorcheck.js') , executing it in-process as Node.js code. The destination is a third-party mutable key-value store whose contents the endpoint owner can change at any time, the URL is stored in base64 form rather than as a plain string, the payload is read from a field named cookie unrelated to its actual use, and execution errors are silently swallowed. The behavior does not match the package's stated purpose as a database connector and provides arbitrary remote code execution against any caller that invokes the method.
Source: amazon-inspector (e6a41259fb0099de58bc669907fa6fb20331d794b13008df0afb42893808e4ab)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.