PoC package for dependency confusion testing - No malicious intent
Installation automatically contacts an external observation endpoint. The callback provides confirmation that the package was installed.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpackage.json automatically runs postinstall.js after installation.
package.jsonView on unpkg · L6package.json frames the package as dependency confusion testing and asserts harmless intent; this does not excuse the active install beacon.
package.jsonView on unpkg · L4Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
postinstall.jsView on unpkgpostinstall.js sends an unsolicited HTTPS beacon to an external OAST endpoint and suppresses errors.
postinstall.jsView on unpkg · L3postinstall.js sends an unsolicited HTTPS beacon to an external OAST endpoint and suppresses errors.
postinstall.jsView on unpkg · L5This report applies to @bluewin/utils@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpackage.json automatically runs postinstall.js after installation.
package.jsonView on unpkg · L6package.json frames the package as dependency confusion testing and asserts harmless intent; this does not excuse the active install beacon.
package.jsonView on unpkg · L4Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
postinstall.jsView on unpkgpostinstall.js sends an unsolicited HTTPS beacon to an external OAST endpoint and suppresses errors.
postinstall.jsView on unpkg · L3postinstall.js sends an unsolicited HTTPS beacon to an external OAST endpoint and suppresses errors.
postinstall.jsView on unpkg · L5