dc-renewals-layout2 @9999.0.0
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC
OSV ID
MAL-2026-12671
Ecosystem
npm
Summary
The package's preinstall script auto-runs on npm install and issues a plaintext HTTP GET to http://75.119.137.232:31337/depconfuse carrying the installer's hostname, username, current working directory, configured npm registry, and CI repository slug environment variables as query parameters. The 9999.0.0 version combined with the /depconfuse endpoint path is the fingerprint of a dependency-confusion reconnaissance beacon: the CI repository slug reveals the names of the installer's private internal packages/repos, which enables targeted follow-on dependency-confusion attacks against the installer's organization. The destination is a hardcoded bare IP on a non-standard port with no relation to the package's declared purpose.
Source: amazon-inspector (6219fbfa414c89e001a734c3cdebf2c059981f1777c937f513198c21e3cbd113)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.