-= Per source details. Do not edit below this line.=-
package.json declares a preinstall hook that runs index.js on npm install. index.js collects host identifiers via os.hostname() and os.userInfo(), reads homedir, DNS server list, and cwd, and reads /etc/passwd and /etc/hosts via fs.readFileSync. The collected data is POSTed over HTTPS to the Burp Collaborator subdomain 0decr93bem6onemg3dmbydi6rxxrli97.oastify.com. The package name suggests an unrelated 'caller id' utility, but the shipped code performs only reconnaissance and exfiltration at install time; no legitimate functionality accompanies the network callback. The oastify.com destination is a Burp Collaborator out-of-band host used for exfiltration/beaconing, not a documented service endpoint of this package.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020285",
"import_time": "2026-09-22T14:19:07.660688103Z",
"modified_time": "2026-09-22T13:56:34Z",
"sha256": "a1adcf7c4b091ee35e021af3f4f886f5c8cc6f34b255315ab9767c3fdda5dcfe",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "71bebad6dd8c6a6bd086b930ae425fe5f3004e8fef4ddf780bce9c3690d803b8",
"tlsh": "5a412399a2c917330dd210c0aa1c70853359fa777259add076cf42969f869f8b7326f3"
}
],
"package_integrity": [
{
"filename": "take-home-caller-id-1.0.1.tgz",
"hashes": {
"sha1": "43f4a54569d52d231882bd3d24e5e45f659cf106",
"sha512_sri": "sha512-vfdO2RUAFQ1/EmXm7ZAQ0aja+XuLVm7iw1bVEKo70bhf7mWvGHi+lc7fqhC1XAdGqoqoLE36Ny42ssqpRT4PlA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/take-home-caller-id/MAL-2026-16382.json"