Logo
npm

@heartlandone-private/fontawesome-pro@6.3.6

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 1:37 AM UTC

Malicious

OSV ID

MAL-2026-11093

Ecosystem

npm

Summary

The package's postinstall lifecycle hook runs node index.js, which issues an HTTPS GET to a hardcoded Burp Collaborator subdomain at e0fumpwx24ddfmenzmg0izs2atgk4es3.oastify.com/dependency-confusion with a User-Agent identifying it as a dependency-confusion probe. On any npm install that resolves this scoped name, the request fires automatically and discloses installer identity (source IP, DNS resolver, timing, request metadata) to a third-party out-of-band interaction server controlled by whoever provisioned the Collaborator instance. The package name uses a private-scope pattern (@heartlandone-private/fontawesome-pro) that mimics an internal artifact, consistent with a dependency-confusion attempt aimed at organizations whose internal @heartlandone-private scope is not reserved on the public registry. Whether the operator's intent is authorized red-team testing or opportunistic exploitation, any consumer whose install pipeline resolves this public package receives install-time code execution and outbound network signalling to an attacker-controlled callback.

Source: amazon-inspector (5dc8f9f53c05ecc2642ce82c3841e046025662c206f002b4c6da11ff0cbc763d)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.