Logo
npm

fr-ito-web-react@99.99.99

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 5:38 AM UTC

Malicious

OSV ID

MAL-2026-14019

Ecosystem

npm

Summary

Package's package.json declares both preinstall and postinstall lifecycle hooks that execute node exfil.js on npm install. exfil.js runs whoami and id via child_process.execSync and transmits the output to the hardcoded host d9vbd1vstrb04vgt4dqg63k7yg55jhmt5.oast.site over HTTPS POST with TLS verification disabled (rejectUnauthorized: false), with a DNS lookup fallback that encodes the whoami output as a hex subdomain of the same collector. The package uses version 99.99.99, a typical dependency-confusion cover version to force resolution over an internal package of the same name. Installer identity and host data leaves the machine to an attacker-controlled interactsh/OAST collector without user interaction.

Source: amazon-inspector (1f8b1f66710b1d0686f5d0a6df5989a01bb20a875e380eed8e4be7b94870372e)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.