fuels-versions@1.0.0
Vulnerability report · Last retrieved from osv.dev September 7, 2026 at 5:03 PM UTC
OSV ID
MAL-2026-15673
Ecosystem
npm
Summary
bin/cli.js contains a hardcoded out-of-band callback URL at https://oobme.kunalsharma0553.workers.dev/r/7bq6fz3l15r9 and, on execution, collects the installer's username (os.userInfo() / whoami), os.hostname(), and os.platform() and POSTs them to that endpoint. The package name resembles the Fuel Labs ecosystem and has the shape of a dependency-confusion / typosquat probe that beacons host identity when the CLI is run (e.g., via npx or as an installed bin).
Source: amazon-inspector (35d9f8a553c586813518fefc4735aa6ee3416720489a27c83b8eff10c1a6a755)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.