OpenSSF/OSV advisory MAL-2026-14137 confirms this npm version as malicious. Package ships an empty index.js and a preinstall lifecycle script that performs a DNS lookup against probe.4otph6fase1x2won0hrfzul2wt2qqge5.oastify.com (Burp Collaborator out-of-band infrastructure). On npm install, the installer's resolver contacts the attacker-controlled subdomain, leaking install-time telemetry (resolver IP, timing, and the unique subdomain identifier) to a third party...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in mtslink-depconf-probe-profileusername (npm)
Details
Package ships an empty index.js and a preinstall lifecycle script that performs a DNS lookup against probe.4otph6fase1x2won0hrfzul2wt2qqge5.oastify.com (Burp Collaborator out-of-band infrastructure). On npm install, the installer's resolver contacts the attacker-controlled subdomain, leaking install-time telemetry (resolver IP, timing, and the unique subdomain identifier) to a third party. The package name pattern and description ('Bug bounty auth probe - safe empty package') indicate a dependency-confusion / typosquat probe targeting an internal namespace; the only functionality is the outbound beacon.
Decision reason
OpenSSF Malicious Packages via OSV confirms mtslink-depconf-probe-profileusername@1.0.0 as malicious (MAL-2026-14137): Malicious code in mtslink-depconf-probe-profileusername (npm)