@coopeuch/config@1.999.999
Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 6:53 PM UTC
OSV ID
MAL-2026-17762
Ecosystem
npm
Summary
The package publishes to the @coopeuch npm scope at version 1.999.999 with a stub index.js, a shape designed to win resolution over an internal scope registry when an organization's scope-to-registry mapping is missing. On npm install, scripts.postinstall executes postinstall.js, which collects host identity (hostname, username, uid/gid, homedir, non-internal network interface addresses and MAC addresses, DNS servers, reverse-DNS internal FQDN), CI/orchestration markers, npm context, container detection via /proc/1/cgroup, and the consuming parent package's name, version, and declared version range, then POSTs the aggregated JSON over HTTPS to the hardcoded author endpoint collector.oob.s4yhii.com/_npm-poc/beacon alongside a DNS beacon under *.oob.s4yhii.com. The behavior fires automatically at install time without consent and reveals internal infrastructure details and private project identifiers of any organization whose build resolves this package from the public registry.
Source: amazon-inspector (0c9b2c76aac3e901d6585717a7e1f9729699bf3a4e280eb20a68bcef4d507d0d)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.