MAL-2026-16235

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/strapi-plugin-osag/MAL-2026-16235.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-16235
Published
2026-09-16T13:59:21Z
Modified
2026-09-16T14:30:06Z
Summary
Malicious code in strapi-plugin-osag (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (34d9349a970008e54774fc533af589248d578e1d34f6f82a9a6630beeabd2203)

The package presents itself as a Strapi plugin but ships no plugin code — only a postinstall.js script that runs automatically on npm install. The script collects installer-side host identifiers (hostname, OS platform/arch/type/release, username, home directory) and enumerates all network interface addresses, then transmits them as query parameters in a plain HTTP GET to a hardcoded Burp Collaborator subdomain 8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com on port 80. The package's declared repository/homepage points at a placeholder github.com/user/strapi-plugin-yayccresh-meeb URL that does not identify a real publisher, and the Strapi-branded name does not match the shipped contents.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-020104",
            "import_time": "2026-09-16T14:19:38.166654663Z",
            "modified_time": "2026-09-16T13:59:21Z",
            "sha256": "34d9349a970008e54774fc533af589248d578e1d34f6f82a9a6630beeabd2203",
            "source": "amazon-inspector",
            "versions": [
                "3.6.8"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / strapi-plugin-osag

Package

Name
strapi-plugin-osag
View open source insights on deps.dev
Purl
pkg:npm/strapi-plugin-osag

Affected ranges

Affected versions

3.*
3.6.8

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "postinstall.js",
            "sha256": "f02e07cef3bdbc71d060b091eab1f15c4bb4ea89ff12e41a0073261f00c98c25",
            "tlsh": "17511fd511ba666421b345c5d59741214122d28a3e02f8fc3dec03e71fdaeecc1726f8"
        },
        {
            "path": "package.json",
            "sha256": "791367c76fd96690863754e4e1376546c153514e55a7835d6df86b4c50d0c8c8",
            "tlsh": "acf04966ca2455a32dec3a94a81a1186a72a4e478c81fc1d23b3011c8f0e2e7747f5dd"
        }
    ],
    "package_integrity": [
        {
            "filename": "strapi-plugin-osag-3.6.8.tgz",
            "hashes": {
                "sha1": "94fc7bdcfd5a3c02205f216cf027947ba048cd5a",
                "sha512_sri": "sha512-eTHA7KgrwRmRnCV8Ke/gAoQfGAdS/T+bhnFQUKLBG/2Q8czY1VMTp8DD37aCb90b29fhXlx7bcxFzajmD5PFHw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/strapi-plugin-osag/MAL-2026-16235.json"