atomic-meta-check
v0.0.2
Published
SECURITY PLACEHOLDER — reserves the unclaimed unscoped bin name of @coveo/atomic-component-health-check to prevent a dependency-confusion (npxconfuse) hijack. This is NOT the real tool; use @coveo/atomic-component-health-check. Reservation only — no insta
Maintainers
Readme
atomic-meta-check — security placeholder (namespace reservation)
This is NOT a functional package. It is a good-faith security reservation.
Why this exists
The unscoped name atomic-meta-check was the unclaimed bin name of the published,
scoped package @coveo/atomic-component-health-check.
Because the scoped package's binary is defined as "bin": { "atomic-meta-check": ... },
anyone running npx atomic-meta-check (the unscoped form, e.g. by dropping the @coveo/
scope) would have fetched whatever was published under this name on the public registry —
a classic dependency-confusion / "npxconfuse" hijack leading to arbitrary code execution
on developer machines, CI runners, and AI agents.
This placeholder was registered by an independent security researcher to prevent a malicious actor from claiming the name first, and to measure whether the name is pulled in the wild.
What it does
- Nothing on install. As of 0.0.2 there is no
postinstallscript and no telemetry — this is a pure namespace reservation. (0.0.1 briefly carried a benign install-context beacon used to demonstrate the vulnerability; it has been removed.) - If executed via
npx, it prints a notice pointing you to the correct scoped package, then exits.
What you should do
Use the real, scoped package instead:
npx @coveo/atomic-component-health-checkFor the Coveo security team
Please publish your own placeholder (or reserve this name) so a real attacker cannot.
Contact the researcher via the Intigriti Coveo program (handle: ghalahad) to have this
reservation transferred to Coveo or unpublished. Full source of this package is exactly the
three files shipped here (package.json, beacon.js, cli.js) — nothing hidden.
