Logo
npm

ubiquiti-agents-link-mcp@0.2.0

Vulnerability report · Last retrieved from osv.dev September 22, 2026 at 11:51 PM UTC

Malicious

OSV ID

MAL-2026-16409

Ecosystem

npm

Summary

The package's bin entry (index.js) runs execSync('id') and collects os.userInfo().username and os.hostname(), then HTTPS-POSTs the JSON payload to the hardcoded Burp Collaborator subdomain uhffaanwxy0io5bfc0icu5lpug07o9cy.oastify.com at a randomized path. The package occupies an npm name referenced by a vendor UI that instructs operators to invoke it via npx, so running the documented command causes host identity data to leave the operator's machine to a third-party OAST endpoint with no opt-in. The tarball metadata self-describes the release as a placeholder registered to demonstrate the dependency-confusion vector, but the shipped code performs a real installer-side data leak on execution, and the namespace remains available for future publishes by the same account with operator-level code execution on any host following the vendor's instruction.

Source: amazon-inspector (8827e987697ea6ef619055c53ae1654800a838c18419ffc8a09e872c6f16adc4)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.