-= Per source details. Do not edit below this line.=-
package.json declares a preinstall script that runs a Node one-liner collecting os.hostname(), process.env.USER/USERNAME, cwd, npmconfigregistry, CI, GITHUBREPOSITORY, JENKINSURL, and platform, base64-encodes the JSON blob, and issues an HTTPS GET to https://aiwi9di43fzbjwncfrimdvkgu701orcg.oastify.com/?d=<base64> on every npm install. index.js is empty, so the package's only effect is this reconnaissance beacon. The oastify.com destination is a Burp Collaborator subdomain used as an attacker-controlled out-of-band exfiltration sink.
{
"malicious-packages-origins": [
{
"sha256": "0c61f9e4ea2d66ea8dd4b9018fa109fe65d00cb0de98b3f8551a95ca3859af5d",
"source": "amazon-inspector",
"versions": [
"6.8.2"
],
"import_time": "2026-08-05T13:08:50.275070367Z",
"modified_time": "2026-08-05T12:59:36Z",
"id": "IN-MAL-2026-014838"
}
]
}{
"evidence_files": [
{
"path": "package.json",
"sha256": "988248624029a2a1d021e1a0ad294d799ba1e74a258f93b4bd313f95de534641",
"tlsh": "f6f0fe2d876cc83b05d10ba025795c879cb2bdaa330898619f53b00e6fe83a2017302f"
}
]
}
[
{
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506",
"name": "Embedded Malicious Code"
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/relativity-foundation-core/MAL-2026-12426.json"