cb-wallet-http@0.0.1
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 6:32 AM UTC
OSV ID
MAL-2026-4507
Ecosystem
npm
Summary
Package name mimics Coinbase's internal cb-wallet-* namespace to capture dependency-confusion resolutions. On npm install (postinstall.js) and on require('cb-wallet-http') (index.js), the package issues an HTTPS GET to the hardcoded endpoint https://icy-cell-fb53.gh0stfqce25.workers.dev/poc, transmitting the package name and Node.js runtime version to a third-party Cloudflare Workers domain registered under a personal handle (gh0stfqce25.workers.dev) unrelated to Coinbase. The package's own description self-identifies as a 'RESERVED PLACEHOLDER — coordinated security-research namespace claim' with the repository github.com/gh0stfqce/npm-namespace-claims. Regardless of the author's stated research intent, any organization that installs this package via misconfigured registry resolution leaks host/build-topology identifiers to the operator of the worker without consent, fingerprinting which builds are vulnerable to dependency confusion against Coinbase's namespace.
Source: amazon-inspector (e8d704c0a6a48da0e2fef8eddcd1f98e7d380c3e19f22753f3df51d9893f60ce)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.