@opap/player-kyc-widget@3.999.999
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC
OSV ID
MAL-2026-14387
Ecosystem
npm
Summary
The package's postinstall script runs automatically on npm install and collects host identifiers (hostname, username, cwd, platform, arch) from the installer, then transmits them off-host through two channels to a hardcoded Burp Collaborator subdomain k5qrs9i96xtw61nb3bbwwualqcw3kt8i.oastify.com: (1) an HTTPS GET carrying a base64-encoded payload in the query string, and (2) a DNS lookup where the fingerprint is hex-encoded and split into <=60-char labels prepended to the callback host, providing a covert channel that works even when outbound HTTP egress is blocked. The version number 3.999.999 published to the public @opap scope is the canonical shape of a dependency-confusion attack targeting a private internal scope of the same name.
Source: amazon-inspector (abfe2a5c5b34e28b415fb39f20acea1ec320ef85aeb9577c9a52153630f964fc)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.