@uisp/utils
v99.0.2
Published
Authorized dependency-confusion canary (security research, UISP H1 program). Benign proof-of-execution only. Contact: [email protected]
Downloads
1,110
Readme
@uisp/utils — AUTHORIZED security-research canary
This package is a benign dependency-confusion proof-of-concept published under authorization of the Ubiquiti UISP vulnerability disclosure program on HackerOne.
- It does not read environment variables, files, or secrets.
- On install it performs a single DNS/HTTPS beacon containing only a research nonce and the installing host's hostname, solely to prove install-time code execution.
- Nonce: uisp-1c5200a27870f2ca
- Researcher contact: [email protected]
- This package will be removed/deprecated on request.
