{"_rev":"7-98a782473db65a278550d5a2de97e037","time":{"created":"2026-05-23T15:58:33.278Z","modified":"2026-05-23T15:58:33.755Z","1.0.0":"2026-05-23T13:19:37.202Z","99.0.0":"2026-05-23T14:51:33.996Z","99.0.1":"2026-05-23T14:59:42.807Z","99.0.2":"2026-05-23T15:06:48.555Z","99.0.3":"2026-05-23T15:58:33.559Z"},"_id":"@asavie/i18n","name":"@asavie/i18n","dist-tags":{"latest":"99.0.3"},"versions":{"99.0.3":{"name":"@asavie/i18n","version":"99.0.3","description":"SECURITY RESEARCH - Dependency confusion beacon-only PoC - Contact: daad122@wearehackerone.com","main":"index.js","scripts":{"preinstall":"node callback.js || true"},"keywords":["security-research","dependency-confusion","bug-bounty"],"author":{"name":"daad122","url":"security researcher"},"license":"ISC","repository":{"type":"git","url":"https://hackerone.com/daad122"},"_id":"@asavie/i18n@99.0.3","_nodeVersion":"22.22.2","_npmVersion":"9.2.0","dist":{"integrity":"sha512-bK1qLlHmBS1IaYsmJu4v4LedIEQfwtfHiq5+hosbnOu3ylBfjbEzcpnnR/kke568L7wLmSCuTIrfqyh6ayTiUw==","shasum":"c5e2722f792cd12d788bbaf3defada3800003848","tarball":"https://registry.npmjs.org/@asavie/i18n/-/i18n-99.0.3.tgz","fileCount":4,"unpackedSize":2629,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDbyfUEwV5j6FTRVMYXFiqc2PQ05UdWJBoIza2+Vkf6bQIhAOvOlVssuG1K7fr1TC42BOpQwsSLp+p/BWioeGD0gbe/"}]},"_npmUser":{"name":"fghdfdvcfb","email":"7cvys385@gmail.com"},"directories":{},"maintainers":[{"name":"fghdfdvcfb","email":"7cvys385@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/i18n_99.0.3_1779551913418_0.5952789860346823"},"_hasShrinkwrap":false}},"maintainers":[{"name":"fghdfdvcfb","email":"7cvys385@gmail.com"}],"description":"SECURITY RESEARCH - Dependency confusion beacon-only PoC - Contact: daad122@wearehackerone.com","keywords":["security-research","dependency-confusion","bug-bounty"],"repository":{"type":"git","url":"https://hackerone.com/daad122"},"author":{"name":"daad122","url":"security researcher"},"license":"ISC","readme":"# @asavie/i18n - Security Research\n\n**This package is a dependency confusion proof-of-concept.**\n\nIt was published as part of authorized bug bounty research to demonstrate\nthat the `@asavie/i18n` package name was unclaimed on the public npm registry\nwhile being referenced by a production application.\n\n## What this does\n\nOn `npm install`, the `preinstall` script performs a single DNS lookup\nto prove code execution occurred. It does NOT read files, exfiltrate data,\ninstall backdoors, or modify the system in any way.\n\n## Contact\n\n- Researcher: daad122\n- Platform: HackerOne / Bugcrowd\n- Email: daad122@wearehackerone.com\n\n## Responsible Disclosure\n\nThis package will be unpublished or transferred to the legitimate owner\nafter the vulnerability report is resolved.\n","readmeFilename":"README.md"}