wos-library-ui @99.0.0
Vulnerability report · Last retrieved from osv.dev August 7, 2026 at 2:10 AM UTC
OSV ID
MAL-2026-13467
Ecosystem
npm
Summary
wos-library-ui@99.0.0 declares scripts.preinstall = 'node poc.js', which auto-runs on npm install. poc.js reads os.hostname(), os.userInfo().username, and process.cwd() and transmits them to the hardcoded Interactsh subdomain csytkgaubytabdgcvgljmgf8o1uj876pg.oast.fun via both a DNS A-record lookup (encoding host/user in the subdomain) and an http.request POST. The package name and inflated 99.0.0 version match the classic dependency-confusion shape targeting an internal 'wos-library-ui' package (self-described as an Inditex WOS PoC): any resolver that prefers the public npm registry will pull this artifact instead of the internal one and execute the beacon, disclosing internal host identifiers and build-path details to a third-party out-of-band collector. Self-labeling as a bug-bounty PoC does not alter the installer-side effect: unconsented install-time exfiltration of installer identity from a namesquatted package on the public registry.
Source: amazon-inspector (3124274f6fcb74cf0805b5545f6952214b90329427f55c616c868f760d592e63)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.