Logo
npm

online-header@99.0.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC

Malicious

OSV ID

MAL-2026-17420

Ecosystem

npm

Summary

online-header@99.0.0 is a dependency-confusion squat (name claimed at version 99.0.0 with an inert main entry) whose preinstall lifecycle script runs node callback.js. callback.js collects host identifiers — os.hostname(), os.userInfo().username, __dirname install path, Node version, os.platform() and os.arch() — and POSTs them via https.request to the hardcoded Burp Collaborator OAST endpoint https://bixi2qq8pkzaq6byt1e037kuul0co2cr.oastify.com, with a DNS-based backup channel to the same subdomain. On any build system that resolves online-header from the public registry (for example, an internal package of the same name shadowed by this public release), npm install automatically transmits the installer's host identity and internal install path to a third-party collector controlled by whoever provisioned the OAST subdomain. The package's self-description as a 'dependency-confusion test' does not change the behavior: installers receive no notice and no opt-out, and the data lands at an endpoint outside their control.

Source: amazon-inspector (4b9cc23b20e29ff5e2382e8812e86048148646c43b844f6f73db4581e790f761)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.