OpenSSF/OSV advisory MAL-2026-5745 confirms this npm version as malicious. oa-crm-webapi@9.9.99 is a dependency-confusion payload squatting an internal-sounding package name. package.json declares a postinstall hook (`node beacon.js`) which fires automatically on `npm install`. beacon.js reads `os.hostname()` and transmits it to the attacker-controlled Burp Collaborator host `yfhjhookbia8zov0q5hh772xroxfl69v.oastify.com` via two channels: a DNS lookup of...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in oa-crm-webapi (npm)
Details
oa-crm-webapi@9.9.99 is a dependency-confusion payload squatting an internal-sounding package name. package.json declares a postinstall hook (`node beacon.js`) which fires automatically on `npm install`. beacon.js reads `os.hostname()` and transmits it to the attacker-controlled Burp Collaborator host `yfhjhookbia8zov0q5hh772xroxfl69v.oastify.com` via two channels: a DNS lookup of `<nonce>.<hostname>.<collaborator-host>` (out-of-band DNS exfil) and an HTTPS POST to the same host with the hostname in the body. The 9.9.99 version + generic 'internal placeholder' description is the canonical shape used to hijack private package names by overriding the legitimate internal registry resolution. A successful install both proves code execution on the installer and leaks the internal hostname to an external attacker.
Decision reason
OSV/OpenSSF confirms oa-crm-webapi@9.9.99 as malicious package MAL-2026-5745. Malicious code in oa-crm-webapi (npm)