npm

lib-frontsga @9.999.999

Vulnerability report · Last retrieved from osv.dev August 7, 2026 at 2:10 AM UTC

Malicious

OSV ID

MAL-2026-13448

Ecosystem

npm

Summary

Package name 'lib-frontsga' published to the public npm registry at version 9.999.999 targets an internal package name via dependency-confusion resolution. A preinstall/postinstall lifecycle script (poc.js) runs on npm install and collects host identifiers (hostname, username, cwd, Node version) together with CI/build attribution (GITHUB_REPOSITORY, GITHUB_REPOSITORY_OWNER, GITHUB_ACTOR, GITHUB_RUN_ID, GITHUB_WORKFLOW, npm_config_registry, RUNNER_NAME, AWS_REGION, and Azure/Jenkins/GitLab identifiers). The collected data is transmitted to a hardcoded Interactsh callback subdomain via DNS queries and HTTP/HTTPS POST to votspfykpbaortacnitltze3m5k5swzg6.oast.fun. Any organization that internally uses this name without a scoped/internal registry pin will resolve this public copy and execute the install-time beacon, disclosing internal build-environment fingerprints to a third-party out-of-band server.

Source: amazon-inspector (53a65c44cfdcbc89df47508f3f87fcab836f1fa2f4adf2298ecfb47cd6088038)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.