Logo
npm

oce-configurator-wireless-frontend@9999.0.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 10:33 AM UTC

Malicious

OSV ID

MAL-2026-15940

Ecosystem

npm

Summary

Package name resembles an internal Swisscom OCE package and is published at version 9999.0.0 to win resolution against a private registry. The preinstall.js lifecycle script, which runs automatically on npm install, collects installer identifiers (os.hostname, os.userInfo().username, process.cwd, __dirname, package name/version, process.platform, node version, npm user-agent) and exfiltrates them to hardcoded external endpoints via three channels: (1) an HTTP/HTTPS POST to /beacon/<token> at the Interactsh collector dae7n4pijsh1ahi9684gu8get3kaiefc9.oast.online with a fallback from HTTPS to plain HTTP on error, (2) a plain-HTTP POST to the bare IP 5.189.159.252, and (3) a DNS side channel where each identifier is hex-encoded (Buffer.from(s).toString('hex').slice(0,60)) and concatenated as subdomain labels of the oast.online host, then resolved via dns.lookup. A hardcoded token 'swisscom-oce-3b9f1c7a2e' correlates the beaconed data with the targeted organization.

Source: amazon-inspector (191e4a78bf46781b56b290aac7b804fd9470b1ac189896b950afbaba548183e6)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.