npm

ir-annuities-client-authentication-module @30.0.0

Vulnerability report · Last retrieved from osv.dev August 29, 2026 at 7:35 AM UTC

Malicious

OSV ID

MAL-2026-15536

Ecosystem

npm

Summary

package.json declares a dependency whose key equals the package's own name ( ir-annuities-client-authentication-module ) and whose value is a plain HTTPS URL to a non-registry host ( https://repo.securityctrl.com/ir-annuities-client-authentication-module ) instead of a semver range. On npm install , npm fetches whatever bytes that URL currently returns and installs them as this dependency, with no version pin, no integrity hash, and no registry provenance; any lifecycle scripts contained in the fetched artifact execute on the installer. The dependency key matching the package's own name creates a dependency-confusion shape that can win resolution against an internal package of the same name. The shipped index.js is an inert stub, so the manifest itself is the delivery mechanism — the absence of local scripts does not prevent the fetch or its lifecycle execution.

Source: amazon-inspector (0d813fc9c0831847a602c97803b7e53603edfb6acef4386e4cde2927c2a7a297)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.