@design-system-coopeuch/web@999.0.4
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 9:46 PM UTC
OSV ID
MAL-2026-3653
Ecosystem
npm
Summary
Package @design-system-coopeuch/web@999.0.4 is a dependency-confusion squat of an internal-looking scope, published at an inflated 999.x version to override any private registry copy. package.json declares a preinstall hook that runs cb.js, which collects installer host identifiers (os.hostname(), cwd, install directory, id, uname -a, OS release info, and the full list of process.env key names) and POSTs them as JSON over cleartext HTTP to a hardcoded bare IP, http://157.173.126.113:8443/dep-confusion (cb.js line 20: hostname: "157.173.126.113", port: 8443, path: "/dep-confusion", method: "POST"). The beacon fires automatically on npm install without user consent. Although the package description self-labels as an "authorized bug bounty PoC," any unintended installer has their host fingerprint exfiltrated to an attacker-controlled endpoint. The combination of internal-scope impersonation, inflated version, and install-time beacon to a bare IP is the canonical dependency-confusion attack shape.
Source: amazon-inspector (a871445c3913d747a2f1383bcfdac02d6dec26ddb2053260340284cf4ee02233)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.