Logo
npm

generate-schema-viem@1.0.0

Vulnerability report · Last retrieved from osv.dev September 6, 2026 at 5:01 AM UTC

Malicious

OSV ID

MAL-2026-15595

Ecosystem

npm

Summary

Package publishes as generate-schema-viem but exposes a bin named generate-schema-ethers (a dependency-confusion / typosquat shape against the generate-schema-* namespace). On CLI invocation, bin/cli.js executes whoami, reads os.hostname() and platform, and POSTs {pkg, whoami, hostname, platform} to the hardcoded endpoint https://oobme.kunalsharma0553.workers.dev/r/7bq6fz3l15r9. The manifest's own description self-labels the package as an OOB callback. Installer identity is leaked to an external attacker-controlled endpoint whenever the tool is invoked on a developer machine or CI runner.

Source: amazon-inspector (82b43ea1e723ebd0c0ef5c4cd564b106089f9b5f9fd119dcac26dc1e130a14bf)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.