-= Per source details. Do not edit below this line.=-
The package's postinstall lifecycle hook runs node index.js, which issues an HTTPS GET to a hardcoded Burp Collaborator subdomain at e0fumpwx24ddfmenzmg0izs2atgk4es3.oastify.com/dependency-confusion with a User-Agent identifying it as a dependency-confusion probe. On any npm install that resolves this scoped name, the request fires automatically and discloses installer identity (source IP, DNS resolver, timing, request metadata) to a third-party out-of-band interaction server controlled by whoever provisioned the Collaborator instance. The package name uses a private-scope pattern (@heartlandone-private/fontawesome-pro) that mimics an internal artifact, consistent with a dependency-confusion attempt aimed at organizations whose internal @heartlandone-private scope is not reserved on the public registry. Whether the operator's intent is authorized red-team testing or opportunistic exploitation, any consumer whose install pipeline resolves this public package receives install-time code execution and outbound network signalling to an attacker-controlled callback.
The OpenSSF Package Analysis project identified '@heartlandone-private/fontawesome-pro' @ 6.3.3 (npm) as malicious.
It is considered malicious because:
6.3.26.3.36.3.6Exploitability
AV:NAC:LPR:NUI:NScope
S:CImpact
C:HI:HA:H10.0/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H