@myorder-frontend-commons/analytics@100.0.0
Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 6:53 PM UTC
OSV ID
MAL-2026-17749
Ecosystem
npm
Summary
Package is published to the public npm scope @myorder-frontend-commons and declares preinstall, install, and postinstall lifecycle scripts all set to node poc.js, so the payload auto-executes on any npm install that resolves this scope. poc.js collects host identifiers (os.hostname(), os.userInfo().username, os.platform()/arch/release, process.cwd(), node version, package metadata, and names of CI-related environment variables) and transmits them via HTTP GET to a hardcoded Interactsh out-of-band subdomain at db4jftohu4noreqdanngpnb3ger45ykrt.oast.fun and a hardcoded IP-based backup collector at 80-190-83-27.nip.io, plus a hex-encoded DNS-label beacon containing the hostname, user, and version. index.js exports stubs that mirror the API shape of an internal package of the same name, which is the dependency-confusion lure: an internal build system that mistakenly resolves against the public registry will install this package and immediately execute the beacon. The payload satisfies the installer-harm gate (install-time code execution plus host-identifier exfiltration to third-party collectors) regardless of any "authorized PoC" framing, because the installer did not consent and the destinations are not controlled by the installer.
Source: amazon-inspector (4e5f7ea46a15cf0b816818dfef340f91e8e4b3b8ac149af84cf133282a90202e)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.