@coopeuch/core@1.999.999
Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 6:53 PM UTC
OSV ID
MAL-2026-17763
Ecosystem
npm
Summary
On npm install, postinstall.js automatically executes and collects a detailed host and environment report — hostname, username, uid/gid, home directory, platform/arch/release, CPU and memory, DNS servers, non-internal network interfaces (name, address, MAC, CIDR), reverse-DNS internal FQDN, container/orchestrator detection, selected npm_* environment variables including scoped registry configuration, CI markers, current working directory, and the parent consuming project's package.json name, version, and declared dependency range. The JSON report is POSTed to https://collector.oob.s4yhii.com/_npm-poc/beacon and a DNS lookup is issued against a subdomain of oob.s4yhii.com as a secondary out-of-band channel. The package is published publicly as @coopeuch/core at version 1.999.999, a version-number shape designed to win resolution against an internal @coopeuch scope — the canonical dependency-confusion attack shape, confirmed by the beacon specifically reporting the consumer's scoped registry env var and internal manifest coordinates. The installer did not consent to disclosing host identity, internal network topology, or the identity of their private project to a third-party host; a self-described proof-of-concept or coordinated-disclosure framing in the package does not change that the code runs unprompted on install and ships installer-identifying data off-host.
Source: amazon-inspector (35a2aead44a4adb850635cf457613400d143b9e4f047767b111058b881cfbb3f)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.