content-publisher-sdks @1.0.1
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC
OSV ID
MAL-2026-12356
Ecosystem
npm
Summary
package.json declares a preinstall hook that runs index.js on npm install. The script collects host reconnaissance (os.hostname(), os.userInfo(), homedir, DNS server list, current working directory, package.json contents) and reads /etc/passwd and /etc/hosts from the installer's filesystem, then POSTs the aggregated JSON over HTTPS to the hardcoded Burp Collaborator subdomain ie02j5ztgjeb6i7tp467ydwnjep8dy1n.oastify.com. The package name mimics a legitimate SDK category but its only behavior on install is this exfiltration beacon.
Source: amazon-inspector (c3faac0139a1c2fd25d8b955e9290380bec365a1d3034fb793dfa723cb930463)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.