Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-11045 confirms this npm version as malicious. package.json declares a postinstall hook that runs index.js on npm install. index.js collects host identifiers (os.hostname(), os.userInfo(), os.platform(), OS release) and enriches them with public IP (via ipify) and geo/ISP (via ipapi.co), then POSTs the JSON payload to a hardcoded Burp Collaborator subdomain at https://dq7q2vt6l79ouvgyzavan3w2rtxkp8gw5.oastify.com/callback...
This report applies to subapp-pkg-util@99.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.