asavie-ui
v99.0.2
Published
SECURITY RESEARCH - Dependency confusion beacon-only PoC - Contact: [email protected]
Maintainers
Readme
asavie-ui - Security Research
This package is a dependency confusion proof-of-concept.
It was published as part of authorized bug bounty research to demonstrate
that the asavie-ui package name was unclaimed on the public npm registry
while being referenced by a production application.
What this does
On npm install, the preinstall script performs a single DNS lookup
to prove code execution occurred. It does NOT read files, exfiltrate data,
install backdoors, or modify the system in any way.
Contact
- Researcher: daad122
- Platform: HackerOne / Bugcrowd
- Email: [email protected]
Responsible Disclosure
This package will be unpublished or transferred to the legitimate owner after the vulnerability report is resolved.
