@bluewin/utils is a dependency-confusion package: it describes itself as a "PoC package for dependency confusion testing" and claims the @bluewin scope, so a build that resolves that scope from the public registry runs its code instead of the intended private package. Its postinstall script runs node postinstall.js on npm install, which sends an HTTPS request to https://5w2cezr3af2i0rvm72x74empvg18pzdo.oastify.com/bluewin/utils, a Burp Collaborator endpoint, disclosing the installing host's IP address and that it installed the package. It collects no further data, but unreviewed code from an outside publisher has run with the installing user's privileges. The npm account securityresearch1 published it on 2026-10-01.
{
"iocs": {
"domains": [
"5w2cezr3af2i0rvm72x74empvg18pzdo.oastify.com"
],
"files": [
{
"digests": {
"sha256": "628e04ce4e3165269e4505b10af93a2df7f689fad6bcbf49409d7be7e18bf300"
},
"note": "postinstall script: node postinstall.js",
"paths": [
"package.json"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "68324659e177d6de76125da39ab3ca96e27a9d3890692a12a652c18471163770"
},
"note": "Executed by the postinstall script of @bluewin/utils@1.0.0.",
"paths": [
"postinstall.js"
],
"source": "PACKAGE_ARCHIVE"
}
],
"urls": [
"https://5w2cezr3af2i0rvm72x74empvg18pzdo.oastify.com/bluewin/utils"
]
}
}