Logo
npm

deposit-limit-fe@100.100.106

Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 6:53 PM UTC

Malicious

OSV ID

MAL-2026-17769

Ecosystem

npm

Summary

deposit-limit-fe@100.100.101 is published as a 'Deposit limit frontend utilities' library but its main entry (index.js) exports an empty object and ships no real functionality. package.json declares postinstall: node postinstall.js, which require()s a bundled Linux x64 native addon at prebuilds/linux-x64/addon.node inside a silenced try/catch. The addon has no corresponding C/C++ source or binding.gyp in the tarball. On load it reads the environment variables HOSTNAME, USER, npm_package_name, and npm_config_registry, forks, opens a TCP socket to the hardcoded bare IP 64.181.165.115, and sends POST /dc HTTP/1.0 with a form-encoded body h=<hostname>&p=<package>&u=<user>&r=<registry>. The anomalous 100.100.101 version and the explicit exfiltration of npm_config_registry are the fingerprint of a dependency-confusion reconnaissance beacon targeting an internal/private npm registry package name. Installing this package automatically leaks the installer's hostname, OS username, and private npm registry URL to an attacker-controlled endpoint and executes opaque native code on the installer's machine.

Source: amazon-inspector (89565d767d3541470834dc9764af6e4abbe4acb5ba4eb721f7e3008e3a80b1d2)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.