@uh-platform/nadaver2@102.0.0
Vulnerability report · Last retrieved from osv.dev September 21, 2026 at 11:45 PM UTC
OSV ID
MAL-2026-16361
Ecosystem
npm
Summary
The package's package.json declares a preinstall lifecycle hook that runs node index.js. index.js invokes child_process.exec on a curl command whose URL embeds $(hostname) and $(whoami) as DNS subdomains of nadaver.pa33pg1od9cr4ffnrzec8864jvpmdd12.oastify.com, a Burp Collaborator (OAST) endpoint. On npm install, the installer's hostname and OS username are transmitted to that attacker-controlled collaborator host via DNS and HTTP. The @uh-platform scope and the name shape are consistent with a dependency-confusion probe. There is no legitimate SDK, build, or install functionality in the package.
Source: amazon-inspector (c35cffdc174427ac57ea3c5e8ac02ec41159f8f25ffe1ef152e0437e5e533458)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.