{"_id":"@goriv/bedrock","name":"@goriv/bedrock","dist-tags":{"latest":"0.999.999"},"versions":{"0.999.999":{"name":"@goriv/bedrock","version":"0.999.999","description":"Security research PoC for Intigriti BBP (Rivian program). Mirror of internal package name @rivian/bedrock referenced in Rivian production bundles. The @rivian npm scope is trademark-protected; @goriv (matches goriv.co internal TLD) was claimable. DNS-only","main":"index.js","scripts":{"postinstall":"node postinstall.js"},"keywords":["security","research","poc","intigriti","bbp"],"author":{"name":"pahpah","url":"Intigriti researcher"},"license":"ISC","homepage":"https://app.intigriti.com/researcher/programs/intigriti/rivian","_id":"@goriv/bedrock@0.999.999","_nodeVersion":"25.9.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-gBQ2VEHpRYtlVR6GdYN31Y10245oJHK2bp7pMEQIYQqYc+GMsctGjdVcL1Mv9WCdJ8gHk9QdhHV1Ed2jAqntvg==","shasum":"e8fd08666732cdca10d0fb275a217306bf6ecf95","tarball":"https://registry.npmjs.org/@goriv/bedrock/-/bedrock-0.999.999.tgz","fileCount":4,"unpackedSize":4492,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIHO3IZBJjXuJHb9UWzXSgMbEoPRJzlSQFA4H0Q9q8NbqAiEAm0tEFCVA8/liL32IYc9vqVGAJ38Qdu+P0D7sXObWY2Q="}]},"_npmUser":{"name":"mickpahpah","email":"mickael.couclet@gmail.com"},"directories":{},"maintainers":[{"name":"mickpahpah","email":"mickael.couclet@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/bedrock_0.999.999_1777887811388_0.5819396661878109"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-04T09:43:31.269Z","0.999.999":"2026-05-04T09:43:31.554Z","modified":"2026-05-04T09:43:31.765Z"},"maintainers":[{"name":"mickpahpah","email":"mickael.couclet@gmail.com"}],"description":"Security research PoC for Intigriti BBP (Rivian program). Mirror of internal package name @rivian/bedrock referenced in Rivian production bundles. The @rivian npm scope is trademark-protected; @goriv (matches goriv.co internal TLD) was claimable. DNS-only","homepage":"https://app.intigriti.com/researcher/programs/intigriti/rivian","keywords":["security","research","poc","intigriti","bbp"],"author":{"name":"pahpah","url":"Intigriti researcher"},"license":"ISC","readme":"# @rivian/eux — security research PoC\n\nThis package is a proof-of-concept for a dependency confusion finding\nsubmitted to Rivian via the Intigriti bug-bounty program.\n\n## Why this exists\n\nRivian's production bundle at `legacy.basecamp.rivian.com/remoteEntry.js`\nreferences the package name `@rivian/eux`. The `@rivian` scope on the\npublic npm registry is unclaimed (404). An attacker who claims the\nscope and publishes a package at any version higher than the internal\n`0.112.1-hotfix.1` will be silently preferred by any build pipeline whose\n`.npmrc` does not pin `@rivian` to Rivian's private registry.\n\nInitial Intigriti report 2026-05-02 was marked Informative on 2026-05-04\nwith the explicit invitation: \"If you can claim the package and provide\nevidence of interactions from Rivian-owned systems, please open a new\nreport.\"\n\nThis package is the response to that invitation.\n\n## What this package does\n\nThe `postinstall` script performs a **single DNS lookup** to a unique\ncallback subdomain so the researcher can correlate which install sites\nfetched the package. The encoded subdomain contains hostname, platform\nand timestamp, nothing else.\n\nIt does **not**:\n\n- Make HTTP requests\n- Read or write files\n- Spawn child processes\n- Read environment variables or credentials\n- Persist anything on disk\n- Download or execute any second-stage payload\n\nThe full source is `postinstall.js` (~25 lines).\n\n## After evidence collection\n\nThis package will be:\n\n1. Unpublished (`npm unpublish --force @rivian/eux`) once Rivian confirms\n   they will register the `@rivian` org themselves, OR\n2. Transferred to Rivian's npm org if they prefer to take it over.\n\n## Contact\n\n- Researcher: pahpah (Intigriti)\n- Email: pahpah@intigriti.me / mickael.couclet@gmail.com\n- Intigriti report: linked from the new submission\n\n## Recommendation to Rivian\n\nRegister the `@rivian` org on npm (free tier sufficient) and publish\nplaceholder packages for at least:\n\n`@rivian/eux`, `@rivian/dt-lib-lumberjack`, `@rivian/legacy`,\n`@rivian/ui`, `@rivian/shell`, `@rivian/components`, `@rivian/utils`,\n`@rivian/auth`, `@rivian/api`.\n\nThen pin `@rivian` to your private registry in every `.npmrc` across CI\nrunners, developer workstations and monorepos.\n","readmeFilename":"README.md","_rev":"1-45f30d3fd68cc537252b0a4386ab251a"}