Logo
npm

@coopeuch/components@1.999.999

Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 6:53 PM UTC

Malicious

OSV ID

MAL-2026-17761

Ecosystem

npm

Summary

The package declares a postinstall script (postinstall.js) that runs automatically on npm install and collects a broad set of installer-side identifiers: hostname, username, uid/gid, home directory, platform, non-internal network interfaces with MAC addresses and CIDRs, configured DNS servers, internal reverse-DNS name, container runtime indicators, npm_* environment variables including the configured registry and scoped registry settings, CI marker variables, and the consuming project's package.json name, version, and declared dependency range for this package. The collected payload is POSTed as JSON to https://collector.oob.s4yhii.com/_npm-poc/beacon, and a DNS lookup beacon is issued against a subdomain of *.oob.s4yhii.com that encodes the package name as a label. The package is published under the @coopeuch scope at an implausibly high version 1.999.999 and specifically introspects the consumer manifest's declared dependency range and the installer's configured registry — a shape consistent with a dependency-confusion squat against an internal scope. Framing the behavior as a 'coordinated disclosure PoC' in author-controlled text does not change what the code does: installers that resolve this package in place of their internal @coopeuch/* package involuntarily disclose host, network, CI, and internal project metadata to a third-party endpoint.

Source: amazon-inspector (042f083be94ae23751c73b5a73c0f11e4e9ecafd9ee9f1caa8c05b367ac71de8)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.