@hzero-front-ui/hzero-ui@99.99.99
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 7:42 AM UTC
OSV ID
MAL-2026-13970
Ecosystem
npm
Summary
Package @hzero-front-ui/hzero-ui@99.99.99 is a scope-lookalike of @hzero-front/hzero-ui with a placeholder version, empty author, generic description, and a trivial index.js. Its package.json preinstall and install lifecycle scripts base64-encode $(whoami):$(hostname):$(pwd):$npm_package_name and send the encoded value to attacker-controlled subdomains of callback.m0chan.co.uk over both HTTPS (curl) and DNS (nslookup). This fires automatically on npm install, leaking the installer's OS username, hostname, current working directory, and the internal package name that resolved to this lure — the canonical dependency-confusion beacon shape.
Source: amazon-inspector (a1b33c04eb2fb12d521b76353993517475d9239c9790c085d16c0c3d0a4ba2f9)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.