@rocketreach/rr-components@9999.0.0
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 1:37 AM UTC
OSV ID
MAL-2026-4427
Ecosystem
npm
Summary
On npm install, both preinstall and postinstall lifecycle hooks execute postinstall.js, which collects host identifiers (hostname, platform, arch, OS username, cwd, Node version) and the full sorted list of process.env key names, then POSTs the JSON payload to a hardcoded https://webhook.site/d81181e1-e40b-478f-a0b4-f18069f9f677 collector. The package name @rocketreach/rr-components at version 9999.0.0 together with the self-identifying proof: "dependency-confusion-poc" field in the payload is the canonical dependency-confusion shape: publishing a high-version package under a target organization's private scope to public npm so that any misconfigured internal build resolves it. Even environment variable NAMES (not values) leak CI secret-naming schemes useful for follow-on attacks. Fires automatically on install with no user interaction.
Source: amazon-inspector (c1c16148ad4c13ad5d5cbfe951d9ca934a0912ab5ad75c3b4afee19be86172fa)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.