ach-details
v99.0.0
Published
AUTHORIZED SECURITY RESEARCH PLACEHOLDER - not a functional package. Published with permission under a BugCrowd bug bounty engagement to demonstrate a dependency confusion condition. Contact pr3da70r via BugCrowd. This package will be unpublished once the
Maintainers
Readme
ach-details — authorized security research placeholder
This is not a functional package. Do not depend on it.
It was published as a proof of concept under an active, authorized bug bounty engagement with Latitude Financial on BugCrowd to demonstrate a dependency confusion condition affecting an internal package of the same name.
If you reached this package by accident
You are almost certainly resolving an internal package name from the public registry. That is the vulnerability. Pin your scope to your private registry. And register the scope as a placeholder on public npm so it cannot be claimed.
Removal
This package will be unpublished as soon as the finding is confirmed, and it will be transferred to Latitude Financial.
Researcher: pr3da70r — contact via BugCrowd.
