airkey-mfa-react @36.1.1
Vulnerability report · Last retrieved from osv.dev July 13, 2026 at 5:39 AM UTC
OSV ID
MAL-2026-6991
Ecosystem
npm
Summary
Package auto-executes a preinstall script ( node test.js ) on npm install that collects username, hostname, platform, Node version, and CI flag and POSTs them to https://eeazmrabqcquvqjfubjp6jkk2qq9p3acn.oast.fun/dex . index.js additionally runs whoami and id via child_process, gathers hostname/uid/gid/homedir/cwd/shell, and POSTs the results to https://rsnchacyin4dnjv0oc8prrwn1e77vzjo.oastify.com/detox56 . The exfil payload carries a package: "company-internal-canary-2026", version: "99.0.0" label, indicating a dependency-confusion probe against an internal package namespace. Both destinations are out-of-band interaction service domains (interact.sh / Burp Collaborator) used to capture installer identifiers.
Source: amazon-inspector (addd30fd6d90110d178ea017b2968c6014dab0e8304bdfeb55b13612a75f61da)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.