{"_id":"@rivianlabs/dc-fe-app-web-rivian-com","_rev":"4-68e96973f8b3d28efa9e9cc381b66078","name":"@rivianlabs/dc-fe-app-web-rivian-com","dist-tags":{"research":"0.0.1-security-research","latest":"0.0.3"},"versions":{"0.0.1-security-research":{"name":"@rivianlabs/dc-fe-app-web-rivian-com","version":"0.0.1-security-research","keywords":["security-research","intigriti","rivian-bug-bounty","dependency-confusion-defense","do-not-use"],"author":{"name":"pahpah","email":"pahpah@intigriti.me"},"license":"Unlicense","_id":"@rivianlabs/dc-fe-app-web-rivian-com@0.0.1-security-research","maintainers":[{"name":"mickpahpah","email":"mickael.couclet@gmail.com"}],"dist":{"shasum":"5a172914ba2aca8e8517d414f2eb4f6ee012cc65","tarball":"https://registry.npmjs.org/@rivianlabs/dc-fe-app-web-rivian-com/-/dc-fe-app-web-rivian-com-0.0.1-security-research.tgz","fileCount":3,"integrity":"sha512-nTI4/V9bGv9W5U7lFSlYD1BcaNT+nRe9zOoHZla5wAV5Vwn0AEmA4HGxIahQFmLkjLqvfge7B4nx9/2myjrbDg==","signatures":[{"sig":"MEYCIQDrKk0ohjgdGeso2UEsT45k9I0S+w969W1E/DESkSlz2wIhAJykF86mSIA1AebgnwlJab1/GKeJfs4LVzQ6Fu/N+7ng","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":4926},"engines":{"node":">=12"},"scripts":{"preinstall":"node ./beacon.js"},"_npmUser":{"name":"mickpahpah","email":"mickael.couclet@gmail.com"},"repository":{"url":"https://intigriti.com/research/rivian-dc-fe-app-web-rivian-com-placeholder","type":"git"},"_npmVersion":"11.12.1","description":"Security research placeholder published as part of authorized Rivian Bug Bounty disclosure (Intigriti report RIVIAN-79L374RT). Triager Aurelius explicitly invited this claim. Intended for transfer to Rivian Inc. Contact: pahpah@intigriti.me","directories":{},"_nodeVersion":"25.9.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/dc-fe-app-web-rivian-com_0.0.1-security-research_1777895733406_0.7094401133465837","host":"s3://npm-registry-packages-npm-production"}},"0.0.1":{"name":"@rivianlabs/dc-fe-app-web-rivian-com","version":"0.0.1","keywords":["security-research","intigriti","rivian-bug-bounty","dependency-confusion-defense","do-not-use"],"author":{"name":"pahpah","email":"pahpah@intigriti.me"},"license":"Unlicense","_id":"@rivianlabs/dc-fe-app-web-rivian-com@0.0.1","maintainers":[{"name":"mickpahpah","email":"mickael.couclet@gmail.com"}],"dist":{"shasum":"27dfd521d8a3d28486c2baee2149dd10b6ff78cf","tarball":"https://registry.npmjs.org/@rivianlabs/dc-fe-app-web-rivian-com/-/dc-fe-app-web-rivian-com-0.0.1.tgz","fileCount":3,"integrity":"sha512-GjmTTVV9rNAlSOPZeCJqL3nw+XnH3zxa2MzoJWcEgkIT37c6yTNJPYSpqQyUuW+tpViV1/zFVh4scwM/go0mbA==","signatures":[{"sig":"MEUCIQCAScQVxFD1oDGyvGiBxDv001y0c4xC6v5TvFrcM0vJMgIgZouQajw99nPU7dSRuj4JONDrD4JRv/DqEwuwgUfLZqA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":4964},"engines":{"node":">=12"},"scripts":{"preinstall":"node ./beacon.js"},"_npmUser":{"name":"mickpahpah","email":"mickael.couclet@gmail.com"},"repository":{"url":"https://intigriti.com/research/rivian-dc-fe-app-web-rivian-com-placeholder","type":"git"},"_npmVersion":"11.12.1","description":"Security research placeholder published as part of authorized Rivian Bug Bounty disclosure (Intigriti report RIVIAN-79L374RT). Triager Aurelius explicitly invited this claim. Intended for transfer to Rivian Inc. Contact: pahpah@intigriti.me","directories":{},"_nodeVersion":"25.9.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/dc-fe-app-web-rivian-com_0.0.1_1778006738141_0.3360934001129865","host":"s3://npm-registry-packages-npm-production"}},"0.0.2":{"name":"@rivianlabs/dc-fe-app-web-rivian-com","version":"0.0.2","keywords":["security-research","intigriti","rivian-bug-bounty","dependency-confusion-defense","do-not-use"],"author":{"name":"pahpah","email":"pahpah@intigriti.me"},"license":"Unlicense","_id":"@rivianlabs/dc-fe-app-web-rivian-com@0.0.2","maintainers":[{"name":"mickpahpah","email":"mickael.couclet@gmail.com"}],"dist":{"shasum":"1e2cd49d5079f99831fe758870933362888dc594","tarball":"https://registry.npmjs.org/@rivianlabs/dc-fe-app-web-rivian-com/-/dc-fe-app-web-rivian-com-0.0.2.tgz","fileCount":3,"integrity":"sha512-+kq51AkPJh4+dVD7UMbrxfDzQpTbjwvJYZJ3onFHF4DVyOKtbiKFoCE+IJ3Ga28ZYsRmbXotHHCSPCcXMGbWuQ==","signatures":[{"sig":"MEYCIQCNDt2RKxhmwQTR14DHUIKO4q7btxFhnaICDm4G7XxFUgIhAN+9HR61V7VG9t6mvTs39E3GhCZPdGtjgDS2O+QvDpvL","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":4964},"engines":{"node":">=12"},"scripts":{"preinstall":"node ./beacon.js"},"_npmUser":{"name":"mickpahpah","email":"mickael.couclet@gmail.com"},"repository":{"url":"https://intigriti.com/research/rivian-dc-fe-app-web-rivian-com-placeholder","type":"git"},"_npmVersion":"11.12.1","description":"Security research placeholder published as part of authorized Rivian Bug Bounty disclosure (Intigriti report RIVIAN-79L374RT). Triager Aurelius explicitly invited this claim. Intended for transfer to Rivian Inc. Contact: pahpah@intigriti.me","directories":{},"_nodeVersion":"25.9.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/dc-fe-app-web-rivian-com_0.0.2_1778006814139_0.7971405304939403","host":"s3://npm-registry-packages-npm-production"}},"0.0.3":{"name":"@rivianlabs/dc-fe-app-web-rivian-com","version":"0.0.3","description":"Security research placeholder published as part of authorized Rivian Bug Bounty disclosure (Intigriti report RIVIAN-79L374RT). Triager Aurelius explicitly invited this claim. Intended for transfer to Rivian Inc. Contact: pahpah@intigriti.me","license":"Unlicense","scripts":{"preinstall":"node ./beacon.js"},"repository":{"type":"git","url":"https://intigriti.com/research/rivian-dc-fe-app-web-rivian-com-placeholder"},"keywords":["security-research","intigriti","rivian-bug-bounty","dependency-confusion-defense","do-not-use"],"author":{"name":"pahpah","email":"pahpah@intigriti.me"},"engines":{"node":">=12"},"_id":"@rivianlabs/dc-fe-app-web-rivian-com@0.0.3","_nodeVersion":"25.9.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-8UBjiZpaY2xfJqhyJU5CKpcyEd5eHshSILL26Rm0BEVuNd5OwPQJu10cALLYfj0Bz6vlTz3ZecWPdFDW/WlC/Q==","shasum":"c3d1d5764df221c232228251c22727e457df8794","tarball":"https://registry.npmjs.org/@rivianlabs/dc-fe-app-web-rivian-com/-/dc-fe-app-web-rivian-com-0.0.3.tgz","fileCount":3,"unpackedSize":4964,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIDeS+gJba0VYkIK3lvbqr4GV1mXMhkoTOFBypVOeWg/kAiEA0sBMmgazVy61Zhf8FwvZdQkfpQRdyq4tYVbZR35d+Wc="}]},"_npmUser":{"name":"mickpahpah","email":"mickael.couclet@gmail.com"},"directories":{},"maintainers":[{"name":"mickpahpah","email":"mickael.couclet@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/dc-fe-app-web-rivian-com_0.0.3_1778007445256_0.23095813366202922"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-04T11:55:33.301Z","modified":"2026-05-05T18:57:25.476Z","0.0.1-security-research":"2026-05-04T11:55:33.532Z","0.0.1":"2026-05-05T18:45:38.288Z","0.0.2":"2026-05-05T18:46:54.277Z","0.0.3":"2026-05-05T18:57:25.375Z"},"author":{"name":"pahpah","email":"pahpah@intigriti.me"},"license":"Unlicense","keywords":["security-research","intigriti","rivian-bug-bounty","dependency-confusion-defense","do-not-use"],"repository":{"type":"git","url":"https://intigriti.com/research/rivian-dc-fe-app-web-rivian-com-placeholder"},"description":"Security research placeholder published as part of authorized Rivian Bug Bounty disclosure (Intigriti report RIVIAN-79L374RT). Triager Aurelius explicitly invited this claim. Intended for transfer to Rivian Inc. Contact: pahpah@intigriti.me","maintainers":[{"name":"mickpahpah","email":"mickael.couclet@gmail.com"}],"readme":"# @rivian/bedrock — Security Research Placeholder\n\n**This is not an official Rivian package.** It is a security research disclosure placeholder published by an Intigriti bug bounty researcher under explicit triager invitation.\n\n## Why this package exists\n\nThe Rivian production web bundles served from `business.rivian.com` and `www.rivian.com` reference the package import name `@rivian/bedrock`. The `@rivian` scope was unclaimed on the public npm registry as of 2026-05-04, meaning any third party could publish arbitrary code under that name and have it installed by Rivian CI/build pipelines that resolve dependencies from the default public registry.\n\nThis placeholder claims the name with a DNS-only, non-intrusive payload and an explicit transfer-to-vendor commitment. Full report:\n\n- Intigriti report ID: **RIVIAN-79L374RT** (rev2)\n- Researcher: pahpah <pahpah@intigriti.me>\n\n## What the package does\n\nOn `npm install @rivian/bedrock`, a single `preinstall` script runs `beacon.js`. That script performs **one DNS resolution** to a researcher-owned Project Discovery interactsh subdomain. It does **not**:\n\n- read any file\n- read any environment variable\n- send anything over HTTP\n- persist anything to disk\n- modify the installer's project\n\nIt only confirms the package was installed somewhere, so the researcher can demonstrate to Rivian's security team that dependency confusion is exploitable on Rivian infrastructure.\n\n## Transfer commitment\n\nThe maintainer of this package will transfer the `@rivian` scope and all packages published under it to Rivian Inc. on first request from a verifiable Rivian security contact (security@rivian.com or via Intigriti).\n\n## Defensive remediation (for Rivian)\n\n1. Claim the `@rivian` scope on public npm (https://www.npmjs.com/org/create).\n2. Publish defensive placeholder versions of every package name referenced in any Rivian production bundle.\n3. Set strict registry routing in every Rivian project's `.npmrc`:\n   ```\n   @rivian:registry=https://<your-internal-registry>/\n   ```\n4. Enforce `--frozen-lockfile` in CI.\n5. Audit and claim the variants: `@rivian-corp`, `@rivianev`, `@rivian-engineering`, `@rivian-internal`, `@rivian-com`, `@drive-tech`, `@drivetech`, `@dt-rivian`, `@dc-rivian`, `@ridg`, `@ridb`, `@rivianlabs`, `@rivianai`. All were unclaimed at disclosure time.\n\n## License\n\nUnlicense — placeholder only, no usable code.\n","readmeFilename":"README.md"}