okra-cloud-cdk@100.0.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17436
Ecosystem
npm
Summary
okra-cloud-cdk@100.0.0 ships a preinstall lifecycle script (setup.js) that runs automatically on npm install. The script collects installer-side identifiers — hostname (os.hostname()), username (os.userInfo().username), current working directory (process.cwd()), platform, architecture, Node version, and the configured npm registry URL (npm_config_registry) — and POSTs them along with a hardcoded token to a hardcoded AWS API Gateway endpoint at https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook. The package's declared main is a trivial zeroPad stub whose functionality (Pad number with leading zeros) is unrelated to the package name okra-cloud-cdk, and the implausibly high version number (100.0.0) is consistent with an attempt to win resolution against an internal package of the same name. The exfiltrated npm_config_registry value in particular discloses internal/private registry hostnames, which are the identifying signal used to select follow-up dependency-confusion targets.
Source: amazon-inspector (84a86d5a0d96567fc1ab65c8f61ab1610b8488859dd53ade8a7a05a86389d371)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.