fuels-core@1.0.0
Vulnerability report · Last retrieved from osv.dev September 6, 2026 at 6:01 AM UTC
OSV ID
MAL-2026-15592
Ecosystem
npm
Summary
The package's bin script (bin/cli.js) collects whoami, os.hostname(), and os.platform() and POSTs them along with the package name to a hardcoded Cloudflare Workers URL (https://oobme.kunalsharma0553.workers.dev/r/7bq6fz3l15r9) with no configuration or opt-out. The bin is exposed as generate-schema-viem, and the package name fuels-core resembles the Fuel ecosystem's fuels package, consistent with typosquat/dependency-confusion reconnaissance targeting installers who resolve or invoke this package (e.g., via npx). The package.json description openly states its purpose is to POST package name and whoami to an OOB callback.
Source: amazon-inspector (c632848960231dec103d878a13a714e057a5922edcc0398884b6fd6d621e0971)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.