Logo
npm

fund-portfolio@999.9.12

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 2:33 PM UTC

Malicious

OSV ID

MAL-2026-14381

Ecosystem

npm

Summary

Package declares scripts.preinstall: node index.js, causing index.js to run automatically on npm install. The script collects hostname, username, home directory, INIT_CWD, local IPv4, public egress IP (via api.ipify.org, icanhazip.com, ifconfig.me), DNS resolver IP and client subnet (via o-o.myaddr.l.google.com), and the parent project's package.json fields (name, author, repository, homepage). The collected JSON is exfiltrated to the hardcoded callback host da51rv0hb2uc72tg4gvgdepinjcallbk1.oast.fun (Interactsh/OAST) via DNS-chunked queries and HTTPS POST to /poc/<uuid>. The unscoped name is published at version 999.9.12 to defeat internal resolvers that fall back to the public npm registry, so any build referencing fund-portfolio without a private-registry pin will resolve to and execute this payload.

Source: amazon-inspector (27ba065e8759299d381ed1c7abd5e7721037b4ea969a384a9e70cfb6bb799e17)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.