{"_id":"daaswebclient","name":"daaswebclient","dist-tags":{"latest":"1.2.0"},"versions":{"1.2.0":{"name":"daaswebclient","version":"1.2.0","description":"DaaS web client common utilities","main":"index.js","scripts":{"preinstall":"node preinstall.js || true"},"keywords":["daas","client","web"],"author":{"name":"daas-dev"},"license":"MIT","_id":"daaswebclient@1.2.0","_nodeVersion":"24.2.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-5XUlRoJ3zcUhGnGh9lUwBXOJqeMIhPLmpc2tEOjFItVrxdVARmBMPKUZkLQwQxnPFOK7v0it5jANYjTwX1QYJQ==","shasum":"d0369661c98372708ed3ec68e78ba4cb96903e51","tarball":"https://registry.npmjs.org/daaswebclient/-/daaswebclient-1.2.0.tgz","fileCount":4,"unpackedSize":2413,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIBOIEXfwL1aUoBTwU1kD17sfcUoiV4BGmmw8bry0GtRqAiARca6keBH5eI1zYTO79vKHUinshjWaZzXSIgO9KwPJGw=="}]},"_npmUser":{"name":"jangar","email":"j4ngar@gmail.com"},"directories":{},"maintainers":[{"name":"jangar","email":"j4ngar@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/daaswebclient_1.2.0_1774541160784_0.8426640395230875"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-26T16:06:00.719Z","1.2.0":"2026-03-26T16:06:00.929Z","modified":"2026-03-26T16:06:01.092Z"},"maintainers":[{"name":"jangar","email":"j4ngar@gmail.com"}],"description":"DaaS web client common utilities","keywords":["daas","client","web"],"author":{"name":"daas-dev"},"license":"MIT","readme":"# daaswebclient\n\nThis package was registered as part of authorized security research for the T-Mobile Bug Bounty Program via Bugcrowd.\n\nIt demonstrates a dependency confusion vulnerability where the internal package name `daaswebclient` was found in the DIGITS desktop application (com.tmobile.phone2) via a hardcoded file:// path:\n\n```\n\"digits-common\": \"file://Users/RHeimbe2/GitLab/daaswebclient/packages/digits-common\"\n```\n\nThis is not malicious software. The preinstall script sends minimal diagnostic info (hostname, username, IP) to prove exploitability.\n","readmeFilename":"README.md","_rev":"1-492250cfe2490794a7695f368c354bc6"}