Logo
npm

@pwaplatform/module-sso-integration@99.0.1

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 1:33 PM UTC

Malicious

OSV ID

MAL-2026-16299

Ecosystem

npm

Summary

@pwaplatform/module-sso-integration@99.0.1 declares both preinstall and postinstall lifecycle scripts that execute payload.js on npm install. payload.js collects hostname, whoami, id, uname -a, the contents of /etc/passwd (up to 4096 bytes), cwd, INIT_CWD, the installing project's git remote and branch, its package.json metadata and top-level dependencies, npm config, CI environment variables, and node/platform information, base64/base64url-encodes the payload, and transmits it over plain HTTP to three hardcoded destinations: http://sobaka-kusaka.ru:8000/oob/<token>, http://sobaka-kusaka.ru:8898/c/<token>, and a Burp Collaborator subdomain at http://ii473egh1b4kbaw03rf7pkzik9q0er8fx.oastify.com/<token>. The @pwaplatform scope name, the implausibly high 99.0.1 version, and the out-of-band collaborator channel are consistent with a dependency-confusion attack against an internal scope; the README's 'authorized bug bounty canary' framing is author-controlled and does not reflect installer consent.

Source: amazon-inspector (4f674867f67f5a8495dbc953913b6cc7c0d8b9d094161c660ca4dfd5449506ba)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.