uolcs-host-uol-anuncios-fe
v99.99.99
Published
Authorized security research — UOL BugHunt program (skysz). Reserved internal package placeholder. No data exfiltration, DNS-only callback for impact verification. Will be unpublished after triage.
Maintainers
Readme
uolcs-host-uol-anuncios-fe (security research placeholder)
This is NOT a real npm package — it is a placeholder published under an internal UOL package name as part of an authorized security research project (UOL BugHunt program).
What this is
The uolcs-host-* package names are used internally by UOL (Universo Online
S.A., Brazil) in their meupainelhost.uol.com.br infrastructure (declared in
their public importmap.json). The name uolcs-host-uol-anuncios-fe was found
to be unclaimed on the public npm registry, which means any third party
could publish a package under that name and have it installed automatically
by UOL's internal Jenkins CI pipeline.
This package was published by an authorized bug bounty researcher (skysz) under
the UOL BugHunt program to demonstrate the impact of this dependency
confusion vulnerability via a single DNS-only callback (no data exfiltration,
no command execution, no file writes — see callback.js).
Why this exists publicly
Because the impact of a dependency confusion attack can only be verified materially by registering one of the unclaimed names and observing CI resolution. Without a public placeholder, the finding remains theoretical.
Will be unpublished
This package will be removed from the npm registry after UOL acknowledges the
underlying vulnerability and applies defensive registration of all 37+ affected
scopes/names (or configures .npmrc with internal registry mapping).
Contact
For questions, please reach out via the UOL BugHunt program.
— skysz, 2026-05-20
