Authorized security PoC (VinSOC engagement). Benign OOB callback only. Do not use. Will be unpublished.
Installing the package automatically sends an out-of-band DNS lookup and HTTP request containing the local hostname. This exposes machine-identifying data to an external OAST service without installer consent.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgAn automatic postinstall hook runs postinstall.js during npm installation.
package.jsonView on unpkg · L7Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe hook collects the installing machine's hostname and incorporates it into a remote hostname.
postinstall.jsView on unpkg · L5The hook performs both a DNS lookup and a plain HTTP request to an external OAST domain.
postinstall.jsView on unpkg · L18Comments and README text try to frame the install-time callback as an authorized benign proof of concept; this is reviewer-directed self-justification.
README.mdView on unpkg · L3This report applies to strapi-plugin-vinsoc-1109@3.6.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgAn automatic postinstall hook runs postinstall.js during npm installation.
package.jsonView on unpkg · L7Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe hook collects the installing machine's hostname and incorporates it into a remote hostname.
postinstall.jsView on unpkg · L5The hook performs both a DNS lookup and a plain HTTP request to an external OAST domain.
postinstall.jsView on unpkg · L18Comments and README text try to frame the install-time callback as an authorized benign proof of concept; this is reviewer-directed self-justification.
README.mdView on unpkg · L3