OpenSSF/OSV advisory MAL-2026-16153 confirms this npm version as malicious. package.json declares `preinstall: node index.js`, causing index.js to execute automatically on `npm install`. The script collects os.hostname(), os.userInfo() (username/uid/gid/shell), platform, arch, homedir, and the stdout of `whoami`, `id`, and `pwd` via child_process.exec, then POSTs the aggregated JSON to a hardcoded endpoint at https://smi54v4uvb9q7ve5t6fnyro16scj0co1.oastify.com/system-info (a Burp...
This report applies to web-main@22.1.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.