OpenSSF/OSV advisory MAL-2026-12790 confirms this npm version as malicious. package.json's preinstall hook runs index.js, which collects hostname, username, home directory, DNS servers, and current working directory, reads /etc/passwd and /etc/hosts, and HTTPS-POSTs the JSON payload to a hardcoded Burp Collaborator (oastify.com) subdomain. The exfiltration fires automatically on npm install without any user interaction, and targets installer-side system identity and account data.
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in glia-functions-tools (npm)
Details
package.json's preinstall hook runs index.js, which collects hostname, username, home directory, DNS servers, and current working directory, reads /etc/passwd and /etc/hosts, and HTTPS-POSTs the JSON payload to a hardcoded Burp Collaborator (oastify.com) subdomain. The exfiltration fires automatically on npm install without any user interaction, and targets installer-side system identity and account data.
Decision reason
OpenSSF Malicious Packages via OSV confirms glia-functions-tools@0.2.1 as malicious (MAL-2026-12790): Malicious code in glia-functions-tools (npm)