Logo
npm

@telekom-ods/react-ui-kit@2.6.9

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 5:38 AM UTC

Malicious

OSV ID

MAL-2026-13770

Ecosystem

npm

Summary

The package.json preinstall hook runs node index.js, which reads os.hostname() and os.userInfo().username and issues an HTTPS GET to a hardcoded subdomain of oast.online, embedding those host identifiers in the URL path (e.g. https://d9t67n4ijf9j5pmd6ug0sij3zd49twn1k.oast.online/telekomDT/<hostname>-<username>). The scope @telekom-ods mimics an internal Deutsche Telekom namespace, and the automatic install-time callout to an out-of-band interaction service is the classic dependency-confusion probe shape: any environment that installs this name reveals its hostname and username to whoever controls the OAST collaborator token. Even if self-described as a research PoC, the published artifact performs unauthenticated exfiltration of installer identifiers on npm install.

Source: amazon-inspector (4b739fe95d8950990211dd6172d27e910aad10de90b7bdd86174ce021c7de676)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.