npm

airkey-mfa-react @36.1.1

Vulnerability report · Last retrieved from osv.dev July 13, 2026 at 5:39 AM UTC

Malicious

OSV ID

MAL-2026-6991

Ecosystem

npm

Summary

Package auto-executes a preinstall script ( node test.js ) on npm install that collects username, hostname, platform, Node version, and CI flag and POSTs them to https://eeazmrabqcquvqjfubjp6jkk2qq9p3acn.oast.fun/dex . index.js additionally runs whoami and id via child_process, gathers hostname/uid/gid/homedir/cwd/shell, and POSTs the results to https://rsnchacyin4dnjv0oc8prrwn1e77vzjo.oastify.com/detox56 . The exfil payload carries a package: "company-internal-canary-2026", version: "99.0.0" label, indicating a dependency-confusion probe against an internal package namespace. Both destinations are out-of-band interaction service domains (interact.sh / Burp Collaborator) used to capture installer identifiers.

Source: amazon-inspector (addd30fd6d90110d178ea017b2968c6014dab0e8304bdfeb55b13612a75f61da)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.