checkmate-remediation-assistant@1.0.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 8:28 PM UTC
OSV ID
MAL-2026-17572
Ecosystem
npm
Summary
The package's package.json declares a preinstall hook that runs index.js on npm install. index.js collects os.hostname(), os.userInfo(), the home directory, DNS server configuration, __dirname, the local package.json, and the contents of /etc/passwd and /etc/hosts, then transmits the collected data over HTTPS to a hardcoded Burp Collaborator (oastify.com) subdomain (9q0lp9mr6ek7nrnklhzkmbpuglmda4yt.oastify.com). The destination is an out-of-band interaction server not associated with any declared publisher or documented package purpose, and the exfiltration fires automatically on default install without user interaction.
Source: amazon-inspector (c8f55d0ebeea19e228ec6edbb1782df87539c476478d3935559fda90a458b1b4)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.