Logo
npm

fuels-typegen@1.0.0

Vulnerability report · Last retrieved from osv.dev September 6, 2026 at 5:01 AM UTC

Malicious

OSV ID

MAL-2026-15593

Ecosystem

npm

Summary

The package name resembles the legitimate @fuel-ts/typegen. On execution of the CLI in bin/cli.js, the code collects the local username (whoami / os.userInfo), os.hostname(), platform, and package name and POSTs them as JSON to the hardcoded endpoint https://oobme.kunalsharma0553.workers.dev/r/7bq6fz3l15r9. The manifest's own description states the package's purpose is to POST identifiers to an out-of-band callback, and the bin name (hyperliquid-composer) is unrelated to the package name, consistent with dependency-confusion or typosquat delivery.

Source: amazon-inspector (f4dcadcdf880021763232df96239a6a07acd6360bfcd941ae8026a37aee2eb2f)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.