@web-monorepo/fetchers
v999.0.0
Published
Authorized security research - dependency confusion validation
Downloads
174
Readme
Security Research - Dependency Confusion Test
This package is part of an authorized security research engagement.
What this does
- Performs a single DNS lookup and HTTPS callback to prove the package was installed
- Reports ONLY: package name, version, hostname, platform, architecture, timestamp
- Does NOT read files, environment variables, secrets, or credentials
- Does NOT persist, install backdoors, or modify the system in any way
Contact
- Platform: BugCrowd
- Researcher: BugCrowd SpectreWire
Remediation
Configure .npmrc to route the @web-monorepo scope to your private registry:
@web-monorepo:registry=https://npm.pkg.github.com