Logo
npm

checkmate-remediation-assistant@1.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 8:28 PM UTC

Malicious

OSV ID

MAL-2026-17572

Ecosystem

npm

Summary

The package's package.json declares a preinstall hook that runs index.js on npm install. index.js collects os.hostname(), os.userInfo(), the home directory, DNS server configuration, __dirname, the local package.json, and the contents of /etc/passwd and /etc/hosts, then transmits the collected data over HTTPS to a hardcoded Burp Collaborator (oastify.com) subdomain (9q0lp9mr6ek7nrnklhzkmbpuglmda4yt.oastify.com). The destination is an out-of-band interaction server not associated with any declared publisher or documented package purpose, and the exfiltration fires automatically on default install without user interaction.

Source: amazon-inspector (c8f55d0ebeea19e228ec6edbb1782df87539c476478d3935559fda90a458b1b4)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.