OpenSSF/OSV advisory MAL-2026-16234 confirms this npm version as malicious. postinstall.js runs automatically on npm install and collects host reconnaissance data — os.hostname(), os.platform(), os.arch(), os.type(), os.release(), the current username, and enumeration of all network interface addresses — then transmits them as query-string parameters in an HTTP GET to hardcoded host 8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com on port 80 at path /osinfo. The oastify.com subdomain is a Burp...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource collects local host identity data and sends it to an external endpoint.
postinstall.jsView on unpkg · L4Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
postinstall.jsView on unpkg · L4This report applies to strapi-plugin-os-rec@3.6.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource collects local host identity data and sends it to an external endpoint.
postinstall.jsView on unpkg · L4Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
postinstall.jsView on unpkg · L4