OpenSSF/OSV advisory MAL-2026-6238 confirms this npm version as malicious. package.json declares "postinstall": "node install.js", which runs automatically on npm install. install.js requires https, fs, os, and child_process; collects host identifiers via os.hostname() and os.userInfo(); invokes execSync() to gather additional system data; checks for sensitive files via fs.existsSync(); and POSTs the collected data over an https.request() to a hardcoded remote endpoint...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in atlasora-client (npm)
Details
package.json declares "postinstall": "node install.js", which runs automatically on npm install. install.js requires https, fs, os, and child_process; collects host identifiers via os.hostname() and os.userInfo(); invokes execSync() to gather additional system data; checks for sensitive files via fs.existsSync(); and POSTs the collected data over an https.request() to a hardcoded remote endpoint. This is the canonical install-time system-information exfiltration shape: any developer or CI machine that runs `npm install atlasora-client` will silently leak host identity, user account info, and reconnaissance data about local filesystem contents to an attacker-controlled destination.
Decision reason
OpenSSF Malicious Packages via OSV confirms atlasora-client@1.0.0 as malicious (MAL-2026-6238): Malicious code in atlasora-client (npm)