-= Per source details. Do not edit below this line.=-
The package's postinstall script reads the installer's machine hostname via os.hostname() and performs a DNS lookup of <hostname>.0ab1mctv5xigbskwtfusp77dj4pvdx1m.oastify.com, leaking the hostname to a Burp Suite Collaborator subdomain at npm install time without consent. oastify.com is the Burp Collaborator service, commonly used by attackers as an out-of-band data-exfiltration channel. The package's advertised functionality is a trivial 5-entry frozen color constants map under the unscoped-looking @uwr scope ("colors for the unified workflow runtime") with an empty author field, consistent with a dependency-confusion / reconnaissance probe staged against an internal namespace rather than a legitimate library.
1.3.6Exploitability
AV:NAC:LPR:NUI:NScope
S:CImpact
C:HI:HA:H10.0/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H