Logo
npm

@convera/ui-shared@0.0.3

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 4:37 AM UTC

Malicious

OSV ID

MAL-2026-3724

Ecosystem

npm

Summary

On npm install, the package's preinstall.js collects os.hostname() and os.userInfo().username and sends them as query parameters (/?hn=<hostname>&un=<username>) via https.request to am0f14nl6o1nqwrngbrq33amfdl496xv.oastify.com, a Burp Collaborator subdomain. The package ships an empty index.js (module.exports = {}) and a package.json description identifying itself as a 'bug-bounty research placeholder — Convera', published under the @convera/* scope to match a private internal namespace. Any installer who resolves this name (accidental scope resolution, misconfigured registry, or a legitimate Convera dev pulling the public registry version) silently leaks host identifiers to a third-party Collaborator endpoint with no opt-in and no functional code in return. Regardless of the author's stated research intent, this is unauthorized data collection from every installer and a dependency-confusion attack surface against the Convera organization.

Source: amazon-inspector (3fa0960816c1204042cecc61c5337e5db2c1407f5325cfc2ed26e43b5dc054d0)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.