Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-16409 confirms this npm version as malicious. The package's bin entry (index.js) runs `execSync('id')` and collects `os.userInfo().username` and `os.hostname()`, then HTTPS-POSTs the JSON payload to the hardcoded Burp Collaborator subdomain `uhffaanwxy0io5bfc0icu5lpug07o9cy.oastify.com` at a randomized path...
This report applies to ubiquiti-agents-link-mcp@0.2.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .