Authorized security research placeholder - dependency confusion proof-of-concept. Not the real package. Will be unpublished after triage.
A preinstall hook exfiltrates host and user installation metadata without a user command. It uses DNS and HTTP(S), including a raw IP address.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe install hook collects the local username, hostname, working directory, install path, platform, Node version, and npm metadata.
preinstall.jsView on unpkg · L39It encodes hostname and username into a DNS lookup and posts the collected JSON to two external destinations.
preinstall.jsView on unpkg · L60It encodes hostname and username into a DNS lookup and posts the collected JSON to two external destinations.
preinstall.jsView on unpkg · L98The hook falls back from HTTPS to plain HTTP, increasing exposure of the collected data.
preinstall.jsView on unpkg · L86This report applies to @caliperx2/components@9999.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe install hook collects the local username, hostname, working directory, install path, platform, Node version, and npm metadata.
preinstall.jsView on unpkg · L39It encodes hostname and username into a DNS lookup and posts the collected JSON to two external destinations.
preinstall.jsView on unpkg · L60It encodes hostname and username into a DNS lookup and posts the collected JSON to two external destinations.
preinstall.jsView on unpkg · L98The hook falls back from HTTPS to plain HTTP, increasing exposure of the collected data.
preinstall.jsView on unpkg · L86