lib-frontsga @9.999.999
Vulnerability report · Last retrieved from osv.dev August 7, 2026 at 2:10 AM UTC
OSV ID
MAL-2026-13448
Ecosystem
npm
Summary
Package name 'lib-frontsga' published to the public npm registry at version 9.999.999 targets an internal package name via dependency-confusion resolution. A preinstall/postinstall lifecycle script (poc.js) runs on npm install and collects host identifiers (hostname, username, cwd, Node version) together with CI/build attribution (GITHUB_REPOSITORY, GITHUB_REPOSITORY_OWNER, GITHUB_ACTOR, GITHUB_RUN_ID, GITHUB_WORKFLOW, npm_config_registry, RUNNER_NAME, AWS_REGION, and Azure/Jenkins/GitLab identifiers). The collected data is transmitted to a hardcoded Interactsh callback subdomain via DNS queries and HTTP/HTTPS POST to votspfykpbaortacnitltze3m5k5swzg6.oast.fun. Any organization that internally uses this name without a scoped/internal registry pin will resolve this public copy and execute the install-time beacon, disclosing internal build-environment fingerprints to a third-party out-of-band server.
Source: amazon-inspector (53a65c44cfdcbc89df47508f3f87fcab836f1fa2f4adf2298ecfb47cd6088038)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.