omni-channel-oid-frontend@9999.0.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC
OSV ID
MAL-2026-15939
Ecosystem
npm
Summary
omni-channel-oid-frontend ships a preinstall.js lifecycle script that fires automatically on npm install. The script collects os.hostname(), os.userInfo().username, cwd, install path, process.platform, Node version and the npm user-agent, and transmits the collected payload via a DNS lookup to an interactsh out-of-band collector at dae7n4pijsh1ahi9684gu8get3kaiefc9.oast.online and via HTTP(S) POST to that same host and to a bare-IP endpoint at 5.189.159.252. The package.json describes the package as a dependency-confusion proof-of-concept placeholder, but the shipped code performs the beacon on every install without installer consent, and the destinations are hardcoded third-party hosts rather than infrastructure the installer configured. Any build that resolves this name during install leaks installer-identifying data to those endpoints.
Source: amazon-inspector (cd8c0fe84f28408bb01adee4ff47b26ed354143c53975559c5d5f2b0a06a61ce)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.