-= Per source details. Do not edit below this line.=-
The package's preinstall hook runs index.js, which collects hostname, username, home directory, DNS servers, package path, and the contents of /etc/passwd and /etc/hosts, then HTTPS-POSTs the JSON payload to the hardcoded Burp Collaborator subdomain tebdjgz4guem6t74pf6iyowyjppgd71w.oastify.com. This fires automatically on npm install with no user interaction.
{
"malicious-packages-origins": [
{
"source": "amazon-inspector",
"versions": [
"1.0.1"
],
"modified_time": "2026-08-05T13:15:58Z",
"import_time": "2026-08-05T14:19:45.855909974Z",
"sha256": "74d01af74706eee07fb8ed306ec3b830641f63b4c055d605026edff65fd11c8f",
"id": "IN-MAL-2026-014949"
}
]
}[
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "71d15307a0ce84833c8ba1ee495bac88d5ad4c00592e6f0b11464423e1b31fa2",
"tlsh": "0041139592c917330dd210c0660c70802359fa767159a9d076cf42969f869f8b7226f3"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/knowledge-grader/MAL-2026-12795.json"