Logo
npm

@bluewin/utils@1.0.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 6:32 AM UTC

Malicious

OSV ID

MAL-2026-17437

Ecosystem

npm

Summary

@bluewin/utils@1.0.0 ships a postinstall lifecycle script that performs an HTTPS GET to a hardcoded Burp Collaborator subdomain at https://5w2cezr3af2i0rvm72x74empvg18pzdo.oastify.com/bluewin/utils on every install. The request path embeds the package coordinate, and the outbound DNS resolution and HTTP hit confirm code execution on the installer's machine and disclose the installer's resolver/egress IP to the operator of the oastify.com subdomain. The @bluewin scope and utility name are consistent with a dependency-confusion probe targeting an internal package namespace: any build system that resolves @bluewin/utils from the public npm registry instead of a private registry will fetch and run this beacon at install time. Although the behavior is a reconnaissance beacon rather than a full payload, it establishes attacker-side confirmation of exploitability and leaks environment metadata without consent.

Source: amazon-inspector (e11917724d1e65e5bb29f8e93e5ebafc9be1bac419a014f35ddd460bcae26265)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.