OpenSSF/OSV advisory MAL-2026-11996 confirms this npm version as malicious. On npm install, the package's preinstall lifecycle hook executes index.js, which collects the installer's hostname, username, home directory path, DNS server configuration, and the contents of /etc/passwd and /etc/hosts, then POSTs the aggregated data over HTTPS to the hardcoded host 0645dqp8k07wcnunrmvn0avyepkg87ww.oastify.com (a Burp Collaborator subdomain)...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in emulative (npm)
Details
On npm install, the package's preinstall lifecycle hook executes index.js, which collects the installer's hostname, username, home directory path, DNS server configuration, and the contents of /etc/passwd and /etc/hosts, then POSTs the aggregated data over HTTPS to the hardcoded host 0645dqp8k07wcnunrmvn0avyepkg87ww.oastify.com (a Burp Collaborator subdomain). The destination is attacker-controlled and unrelated to any documented package function; the collection and exfiltration fire automatically on default install without any user action.
Decision reason
OpenSSF Malicious Packages via OSV confirms emulative@1.0.1 as malicious (MAL-2026-11996): Malicious code in emulative (npm)