ocfe-tv-subscription-center-web@9999.0.0
Vulnerability report · Last retrieved from osv.dev September 8, 2026 at 10:08 PM UTC
OSV ID
MAL-2026-15941
Ecosystem
npm
Summary
Package name resembles an internal-scoped name and uses an implausibly high version (9999.0.0) consistent with dependency-confusion targeting. The preinstall.js lifecycle script runs automatically on npm install and collects installer identifiers (os.hostname, os.userInfo().username, cwd, __dirname, platform/os.release, node version, npm user-agent, resolved package name and version) and transmits them through three channels to author-controlled destinations: a DNS lookup whose subdomain labels are hex-encoded fields (token, package name, hostname, username) appended to dae7n4pijsh1ahi9684gu8get3kaiefc9.oast.online, an HTTPS POST to the same interactsh host, and an HTTP POST to the bare IP 5.189.159.252. The DNS channel provides a covert side-channel that bypasses HTTP-only egress filtering. A self-labelled 'bug bounty research' header in the file does not change the behavior: installing this package causes installer-side identifiers to leave the machine to hardcoded, non-configurable endpoints.
Source: amazon-inspector (87b1dcb639402e9d94a5f6f171e32ed97eb7064f7a557b1f7382bf832a4415ba)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.