Logo
npm

omni-channel-order-frontend@9999.0.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC

Malicious

OSV ID

MAL-2026-15942

Ecosystem

npm

Summary

The package name and 9999.0.0 version are consistent with a dependency-confusion lure targeting an internal omni-channel-order-frontend package. package.json declares a preinstall script (preinstall.js) that fires automatically on npm install. On execution it collects installer identifiers — os.hostname(), os.userInfo().username, current working directory, install path, process.platform/OS release, Node version, npm user-agent, and the resolved package name+version — and transmits them to hardcoded external destinations via three channels: a hex-encoded DNS-subdomain lookup to the Interactsh OAST collector dae7n4pijsh1ahi9684gu8get3kaiefc9.oast.online, an HTTPS POST to the same OAST host, and a plain-HTTP POST to the bare IP 5.189.159.252. Identifiers are hex-encoded into DNS labels so the fields still reach the attacker's authoritative resolver when HTTP egress is blocked. A swisscom-oce-* token embedded in the beacon tags the victim organization. Self-labeling in the source as an authorized bug-bounty PoC is author-controlled text and is inconsistent with a public-registry release using an implausibly high version number to win dependency resolution against an internal package.

Source: amazon-inspector (b5286224ab4427b1e85bbdfd5e57b9d96fc9736504d17f2f31839562f19b88ee)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.