Logo
npm

@uh-platform/nadaver2@102.0.0

Vulnerability report · Last retrieved from osv.dev September 21, 2026 at 11:45 PM UTC

Malicious

OSV ID

MAL-2026-16361

Ecosystem

npm

Summary

The package's package.json declares a preinstall lifecycle hook that runs node index.js. index.js invokes child_process.exec on a curl command whose URL embeds $(hostname) and $(whoami) as DNS subdomains of nadaver.pa33pg1od9cr4ffnrzec8864jvpmdd12.oastify.com, a Burp Collaborator (OAST) endpoint. On npm install, the installer's hostname and OS username are transmitted to that attacker-controlled collaborator host via DNS and HTTP. The @uh-platform scope and the name shape are consistent with a dependency-confusion probe. There is no legitimate SDK, build, or install functionality in the package.

Source: amazon-inspector (c35cffdc174427ac57ea3c5e8ac02ec41159f8f25ffe1ef152e0437e5e533458)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.