Logo
npm

cb-wallet-http@0.0.1

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 6:32 AM UTC

Malicious

OSV ID

MAL-2026-4507

Ecosystem

npm

Summary

Package name mimics Coinbase's internal cb-wallet-* namespace to capture dependency-confusion resolutions. On npm install (postinstall.js) and on require('cb-wallet-http') (index.js), the package issues an HTTPS GET to the hardcoded endpoint https://icy-cell-fb53.gh0stfqce25.workers.dev/poc, transmitting the package name and Node.js runtime version to a third-party Cloudflare Workers domain registered under a personal handle (gh0stfqce25.workers.dev) unrelated to Coinbase. The package's own description self-identifies as a 'RESERVED PLACEHOLDER — coordinated security-research namespace claim' with the repository github.com/gh0stfqce/npm-namespace-claims. Regardless of the author's stated research intent, any organization that installs this package via misconfigured registry resolution leaks host/build-topology identifiers to the operator of the worker without consent, fingerprinting which builds are vulnerable to dependency confusion against Coinbase's namespace.

Source: amazon-inspector (e8d704c0a6a48da0e2fef8eddcd1f98e7d380c3e19f22753f3df51d9893f60ce)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.