npm

dbk-ui-forms @99.0.1

Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC

Malicious

OSV ID

MAL-2026-12669

Ecosystem

npm

Summary

On npm install , the package's preinstall hook runs index.js which collects host identity (hostname, username, homedir, network interfaces, uid), output of whoami / id / pwd / uname -a , and the names of process.env variables matching a broad credential regex (key/token/secret/pass/auth/cred/npm/ci/build/jenkins/github/gitlab/aws/azure). The collected JSON is transmitted to the hardcoded Interactsh subdomain ycwyyoimdcluajepubah2mvmkibt4h5wm.oast.fun via HTTPS POST, HTTP POST, and DNS-encoded lookups. The package name and version (99.0.1) are consistent with a dependency-confusion beacon targeting internal build systems that resolve an unclaimed name from the public registry.

Source: amazon-inspector (36c6972ca0999559f2a4548843790c8000451acb4869da3c83d0357a655586ba)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.