OpenSSF/OSV advisory MAL-2026-14438 confirms this npm version as malicious. package.json declares `preinstall: node index.js`, so `npm install` automatically runs index.js. index.js reads os.hostname(), os.userInfo(), the user home directory, DNS server configuration, and the contents of /etc/passwd and /etc/hosts, and POSTs the collected data over HTTPS to the hardcoded host 7iqn7pls4ly6w8valba0xcxygpmha7yw.oastify.com (a Burp Collaborator / OAST subdomain used as an attacker-controlled...
This report applies to remove-bg-serverless-azure@1.1.1.
1.0.1, 1.1.1
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.