com.db.dbk.ui-forms@99.0.1
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 7:32 AM UTC
OSV ID
MAL-2026-12355
Ecosystem
npm
Summary
com.db.dbk.ui-forms@99.0.1 is a version-inflated package published to the public npm registry under a scope that resembles an internal namespace. Its package.json declares preinstall: node index.js, which runs automatically on npm install. index.js collects host identifiers (os.hostname(), os.platform(), os.userInfo(), homedir, network interfaces) and the output of shell commands (uname, id, whoami) via child_process, and enumerates process.env for keys matching /key|token|secret|pass|auth|cred|npm|ci|build|jenkins|github|gitlab|aws|azure/i. The collected payload is POSTed via https.request/http.request to the hardcoded interactsh callback host ycwyyoimdcluajepubahl0tpb7943a2z4.oast.fun at path /dcf/<pkg>, with a base64-chunked copy also emitted via DNS lookups to the same host. The package.json self-describes as a dependency confusion proof of concept; the installer-side behavior is exfiltration regardless of that framing.
Source: amazon-inspector (c74649b28994f970d4972ffb8708378b355186eb729bf2e4c45d6acd16346e5d)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.