Logo
npm

@asdfaskdjfksadhfkasf/nadaver2@102.0.0

Vulnerability report · Last retrieved from osv.dev September 21, 2026 at 11:45 PM UTC

Malicious

OSV ID

MAL-2026-16357

Ecosystem

npm

Summary

The package declares a preinstall lifecycle script that executes index.js on npm install. index.js uses child_process.exec to run a curl command whose URL embeds $(hostname) and $(whoami) as subdomains of sgc6vj7rjciuailqx2kfebc7pyvpjk79.oastify.com, a Burp Collaborator (OAST) host. On install, the installer's hostname and username are transmitted to that attacker-controlled destination via DNS resolution and HTTP. The package name is a random alphanumeric scope with no legitimate functionality; the sole observable behavior is host reconnaissance exfiltration at install time. This is the canonical dependency-confusion / OAST recon payload shape.

Source: amazon-inspector (ffa99497d70b8eae199242d576c111b7b351efcf5d81d613e3f7b43eec257f27)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.