Logo
npm

@sflyinc-knapsack/shutterfly-react@999.0.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 9:32 AM UTC

Malicious

OSV ID

MAL-2026-5393

Ecosystem

npm

Summary

On require/load, index.js collects host identifiers (os.hostname(), os.userInfo(), os.homedir()), DNS server configuration, package.json metadata, and __dirname, then HTTPS-POSTs them to nlc574f24tq03k423v3jr7hllcr3ft3i.oastify.com — a Burp Collaborator (OAST) subdomain. The package is published at version 999.0.0 under a scope mimicking an internal Shutterfly namespace, designed to win npm version resolution against the legitimate private package. Any installer who imports this package leaks host and internal-package metadata to an attacker-controlled endpoint. The package's own description self-identifies as a dependency-confusion proof-of-concept, but the live registry artifact still executes against any consumer that resolves it.

Source: amazon-inspector (d1b554d911cfb6d444727262a62e2db10f22a75d53d23741d6c2684f62fb6e5d)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.