@aonunited/angular
v99.0.1
Published
Security research - Dependency confusion PoC for authorized VDP testing on HackerOne (https://hackerone.com/aon). This package is benign and only performs a DNS lookup to verify installation. No data is exfiltrated. Contact: [email protected]
Downloads
443
Maintainers
Readme
@aonunited/angular — Security Research PoC
This package is a benign proof-of-concept for authorized security research.
Purpose
This package was published as part of a Dependency Confusion vulnerability assessment conducted under Aon's Vulnerability Disclosure Program (VDP) on HackerOne: https://hackerone.com/aon
What it does
On installation, this package performs a single DNS lookup to a researcher-controlled
domain to verify that the package was installed. This proves that the npm scope
@aonunited was unclaimed and that a supply chain attack was possible.
What it does NOT do
- Does NOT read, write, or modify any files
- Does NOT exfiltrate any sensitive data
- Does NOT establish any network connections beyond a single DNS query
- Does NOT persist or install any backdoors
Contact
If you are from Aon's security team and have questions about this package, please reach out via HackerOne or at [email protected].
Remediation
Aon should register the @aonunited organization on npmjs.com and claim
this package namespace. This package can then be unpublished or transferred
to Aon's ownership.
