npm

crm-reportinsightserv-paypal @28.0.0

Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 1:58 AM UTC

Malicious

OSV ID

MAL-2026-11098

Ecosystem

npm

Summary

crm-reportinsightserv-paypal@28.0.0 executes a preinstall script (index.js) that collects installer host identifiers — os.hostname(), os.platform(), os.arch(), os.homedir(), and dns.getServers() — and POSTs them to the hardcoded Burp Collaborator subdomain x75kp5s6h5jveprlhbibqpi4nvtnhe53.oastify.com/hit at npm install time. The package name mimics an internal-sounding scope (PayPal / CRM reporting) and its only functional behavior is the beacon, matching the shape of a dependency-confusion reconnaissance package.

Source: amazon-inspector (ed758e4154bc29bda7b5ee78165766980d88068090a9853a2243509d97c11152)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.