OpenSSF/OSV advisory MAL-2026-12816 confirms this npm version as malicious. package.json declares a preinstall hook that runs index.js during `npm install`. The script reads /etc/passwd, /etc/hosts, os.hostname(), os.userInfo().username, the user's home directory, dns.getServers(), and package metadata, then POSTs the collected data via HTTPS to the hardcoded subdomain 7ckdbwo9f8dtrg8y36sbe4e8lzrqfg35.oastify.com (Burp Collaborator OAST callback)...
This report applies to wolverinechat@1.1.1.
1.0.1, 1.1.1
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.