Security PoC NETPROVIDER- dependency confusion
Installing the package automatically contacts an external host with local account and host identifiers. This is an unconsented install-time data-exfiltration callback.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe preinstall hook sends the current username and hostname to an external OAST host during installation.
package.jsonView on unpkg · L6Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgAn npm script contacts a known out-of-band callback or webhook service.
package.json#scripts.preinstallView on unpkgAn npm script sends host identity through command substitution to a fixed external destination.
package.json#scripts.preinstallView on unpkgThis report applies to app-rrhh@999.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe preinstall hook sends the current username and hostname to an external OAST host during installation.
package.jsonView on unpkg · L6Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgAn npm script contacts a known out-of-band callback or webhook service.
package.json#scripts.preinstallView on unpkgAn npm script sends host identity through command substitution to a fixed external destination.
package.json#scripts.preinstallView on unpkg