OpenSSF/OSV advisory MAL-2026-10081 confirms this npm version as malicious. The package declares a preinstall hook (`node index.js`) that fires automatically on `npm install`. The script requires `child_process`, `os`, `https`, and `http`, collects hostname, platform, arch, username/uid/gid, shell, home directory, CPU/memory stats, cwd, and the output of `whoami`/`id`, then POSTs the JSON payload to a hardcoded Burp Collaborator (oastify.com) subdomain at...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
index.jsView on unpkg · L1Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
index.jsView on unpkg · L1