`@vpms/design-system` - internal-scope dependency-confusion with preinstall env-var exfil to Pipedream
On 2026-06-25 between 15:52 UTC and 17:14 UTC, an operator published four versions of @vpms/design-system (0.1.3, 1.0.0, 1.0.1, 1.1.2) as a dependency-confusion attack against the internal @vpms scope. The preinstall script iterates process.env and harvests every variable whose name contains SECRET, TOKEN, PASSWORD, KEY, or CREDENTIAL, along with hostname, username, and process details, then exfiltrates the payload to a hardcoded Pipedream webhook at eov0bmnid410yqf.m.pipedream.net. npm-support replaced all four versions with a 0.0.1-security holder on 2026-06-29.
Versions named here: 0.1.3, 1.0.0, 1.0.1, 1.1.2