Use of software with malware In @mrbenty8jf1p9y5/oidc-bind-canary
Description
The package's postinstall lifecycle script issues an HTTPS request from the installer's machine to a Cloudflare tunnel at wiki-shared-carlos-exempt.trycloudflare.com on path /token-capture. The request is sent with the Host header spoofed to dependabot-api.githubapp.com and with TLS certificate validation disabled (rejectUnauthorized:false), disguising the callout as legitimate GitHub Dependabot traffic. The destination path name (/token-capture) and the disguise mechanics indicate an install-time beacon to an attacker-controlled listener, firing automatically on npm install.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version |
|---|---|---|
npm |
Aliases