-= Per source details. Do not edit below this line.=-
The package presents itself as a Strapi plugin but ships no plugin code — only a postinstall.js script that runs automatically on npm install. The script collects installer-side host identifiers (hostname, OS platform/arch/type/release, username, home directory) and enumerates all network interface addresses, then transmits them as query parameters in a plain HTTP GET to a hardcoded Burp Collaborator subdomain 8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com on port 80. The package's declared repository/homepage points at a placeholder github.com/user/strapi-plugin-yayccresh-meeb URL that does not identify a real publisher, and the Strapi-branded name does not match the shipped contents.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020104",
"import_time": "2026-09-16T14:19:38.166654663Z",
"modified_time": "2026-09-16T13:59:21Z",
"sha256": "34d9349a970008e54774fc533af589248d578e1d34f6f82a9a6630beeabd2203",
"source": "amazon-inspector",
"versions": [
"3.6.8"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "postinstall.js",
"sha256": "f02e07cef3bdbc71d060b091eab1f15c4bb4ea89ff12e41a0073261f00c98c25",
"tlsh": "17511fd511ba666421b345c5d59741214122d28a3e02f8fc3dec03e71fdaeecc1726f8"
},
{
"path": "package.json",
"sha256": "791367c76fd96690863754e4e1376546c153514e55a7835d6df86b4c50d0c8c8",
"tlsh": "acf04966ca2455a32dec3a94a81a1186a72a4e478c81fc1d23b3011c8f0e2e7747f5dd"
}
],
"package_integrity": [
{
"filename": "strapi-plugin-osag-3.6.8.tgz",
"hashes": {
"sha1": "94fc7bdcfd5a3c02205f216cf027947ba048cd5a",
"sha512_sri": "sha512-eTHA7KgrwRmRnCV8Ke/gAoQfGAdS/T+bhnFQUKLBG/2Q8czY1VMTp8DD37aCb90b29fhXlx7bcxFzajmD5PFHw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/strapi-plugin-osag/MAL-2026-16235.json"