OpenSSF/OSV advisory MAL-2026-11055 confirms this npm version as malicious. On npm install, the package's preinstall lifecycle executes index.js which collects os.hostname(), os.platform(), and os.arch() and POSTs them as JSON over HTTPS to the hardcoded subdomain rpke7za0zz1pwj9fz5058j0y5pbgz82wr.oastify.com — a Burp Collaborator out-of-band collector...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in fundraiserservicepp (npm)
Details
On npm install, the package's preinstall lifecycle executes index.js which collects os.hostname(), os.platform(), and os.arch() and POSTs them as JSON over HTTPS to the hardcoded subdomain rpke7za0zz1pwj9fz5058j0y5pbgz82wr.oastify.com — a Burp Collaborator out-of-band collector. The package provides no advertised functionality beyond this beacon and matches the dependency-confusion probe shape, with installer host identifiers leaving the machine automatically to a third-party OOB endpoint the installer did not opt into.
## Source: ossf-package-analysis (cefb4588a67439c112176df4b9af71d40a1e2a12e0bf81ef200affa79e0cb0e0) The OpenSSF Package Analysis project identified 'fundraiserservicepp' @ 1.5.0 (npm) as malicious.
It is considered malicious because:
- The package communicates with a domain associated with malicious activity.
Decision reason
OpenSSF Malicious Packages via OSV confirms fundraiserservicepp@1.7.0 as malicious (MAL-2026-11055): Malicious code in fundraiserservicepp (npm)