vue-demi-fix @10.0.5
Vulnerability report · Last retrieved from osv.dev July 1, 2026 at 10:05 PM UTC
OSV ID
MAL-2026-6702
Ecosystem
npm
Summary
vue-demi-fix is a name-confusion package against the widely used vue-demi library. package.json declares both preinstall and postinstall lifecycle scripts that invoke curl against a hardcoded bare-IP HTTP endpoint (http://109.71.252.153:8080/), exfiltrating the installer's OS, username (whoami), current working directory (pwd), and hostname as URL query parameters on every npm install. The package ships no real functionality — index.js only prints a proof-of-concept notice and README self-labels as a 'Responsible Disclosure' PoC. Regardless of the PoC framing, installers receive no benign function and their host identity is unconditionally beaconed to a non-publisher, non-registry endpoint on a default install.
Source: amazon-inspector (3bf683b6e8715fecd451a06da256d90048054cbe463da64e43c1a8db4226b661)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.