OpenSSF/OSV advisory MAL-2026-16235 confirms this npm version as malicious. The package presents itself as a Strapi plugin but ships no plugin code — only a postinstall.js script that runs automatically on `npm install`...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource collects local host identity data and sends it to an external endpoint.
postinstall.jsView on unpkg · L4Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
postinstall.jsView on unpkg · L4This report applies to strapi-plugin-osag@3.6.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource collects local host identity data and sends it to an external endpoint.
postinstall.jsView on unpkg · L4Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
postinstall.jsView on unpkg · L4