OpenSSF/OSV advisory MAL-2026-16192 confirms this npm version as malicious. The package's postinstall.js (also declared as main) executes automatically on npm install and performs bulk host reconnaissance and credential theft against the installer. It captures os.hostname() and os.userInfo(), serializes the full process.env, reads Strapi configuration under /app/config/* and /app/.env*, recursively walks the filesystem from '/' to collect files matching.env* and private-key/certificate...
This report applies to strapi-plugin-weccresh-meeb@3.6.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.