OpenSSF/OSV advisory MAL-2026-12809 confirms this npm version as malicious. package.json declares `preinstall: node index.js`, causing index.js to run automatically on `npm install`. The script collects installer-side data — hostname, username, home directory, DNS server list, current working directory, package.json contents, and the contents of /etc/passwd and /etc/hosts — and HTTPS-POSTs it to a hardcoded Burp Collaborator subdomain at 5z5h9l8e7cktx1ihl6usn4zgb7h15rtg.oastify.com...
This report applies to technical-challenge@1.1.1.
1.0.1, 1.1.1
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.