@wbnr/design@99.3.0
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 2:37 AM UTC
OSV ID
MAL-2026-11196
Ecosystem
npm
Summary
The package's preinstall lifecycle script runs automatically on npm install. It reads the installer's username (from USER/USERNAME environment variables) and the machine hostname (via os.hostname()), then embeds those identifiers along with the package name and a timestamp into both a DNS lookup and an HTTPS GET request directed at a hardcoded Burp Collaborator subdomain, 4otph6fase1x2won0hrfzul2wt2qqge5.oastify.com. The package name and scope (@wbnr) and its self-description indicate a dependency-confusion payload targeting an internal organization scope; any environment that resolves @wbnr/design from public npm will leak installer host identifiers to the attacker-controlled out-of-band endpoint. The 'harmless bug bounty PoC' framing in the package description does not change the observable behavior: installer-owned identifiers leave the machine to a third-party OOB collector on install.
Source: amazon-inspector (1dcfb8ede925ca9e0cf7574c2ba3f81ced56682ef6c54439cc00ad5fc5b960fd)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.