Logo
npm

@rocketreach/rr-components@9999.0.0

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 1:37 AM UTC

Malicious

OSV ID

MAL-2026-4427

Ecosystem

npm

Summary

On npm install, both preinstall and postinstall lifecycle hooks execute postinstall.js, which collects host identifiers (hostname, platform, arch, OS username, cwd, Node version) and the full sorted list of process.env key names, then POSTs the JSON payload to a hardcoded https://webhook.site/d81181e1-e40b-478f-a0b4-f18069f9f677 collector. The package name @rocketreach/rr-components at version 9999.0.0 together with the self-identifying proof: "dependency-confusion-poc" field in the payload is the canonical dependency-confusion shape: publishing a high-version package under a target organization's private scope to public npm so that any misconfigured internal build resolves it. Even environment variable NAMES (not values) leak CI secret-naming schemes useful for follow-on attacks. Fires automatically on install with no user interaction.

Source: amazon-inspector (c1c16148ad4c13ad5d5cbfe951d9ca934a0912ab5ad75c3b4afee19be86172fa)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.