0vulns-dependency-confusion-poc@1.0.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 9:32 AM UTC
OSV ID
MAL-2025-5016
Ecosystem
npm
Summary
The package.json preinstall script runs wget against an attacker-controlled webhook.site URL, passing $(whoami), $(pwd), and $(hostname) as query parameters, executing automatically on npm install. This matches the npm-lifecycle-external-fetch and credential/telemetry exfiltration patterns (findings a static pattern match, a static pattern match, a static pattern match, a static pattern match, a static pattern match). the analysis confirms contextually that the script performs reconnaissance exfiltration to a non-registry collector, and config.unsafe-perm is set to ensure execution. the analysis further notes that the declared main entrypoint is missing and the tarball contains only package.json — the package exists solely to trigger the beacon, with no legitimate runtime functionality. Self-identification as a 'PoC' does not change the risk to an unintended installer (e.g., via dependency confusion).
Source: amazon-inspector (3d282025fb2ec1b4012e3b979cec1f66520e643fcadfd2864e54989de50dd00d)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.