Logo
npm

fuels-versions@1.0.0

Vulnerability report · Last retrieved from osv.dev September 7, 2026 at 5:03 PM UTC

Malicious

OSV ID

MAL-2026-15673

Ecosystem

npm

Summary

bin/cli.js contains a hardcoded out-of-band callback URL at https://oobme.kunalsharma0553.workers.dev/r/7bq6fz3l15r9 and, on execution, collects the installer's username (os.userInfo() / whoami), os.hostname(), and os.platform() and POSTs them to that endpoint. The package name resembles the Fuel Labs ecosystem and has the shape of a dependency-confusion / typosquat probe that beacons host identity when the CLI is run (e.g., via npx or as an installed bin).

Source: amazon-inspector (35d9f8a553c586813518fefc4735aa6ee3416720489a27c83b8eff10c1a6a755)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.