npm

dojo-rn-interview @1.0.1

Vulnerability report · Last retrieved from osv.dev August 8, 2026 at 12:14 AM UTC

Malicious

OSV ID

MAL-2026-13549

Ecosystem

npm

Summary

dojo-rn-interview@1.0.1 declares a preinstall script that runs index.js on npm install . The script collects host identifiers via os.hostname(), os.userInfo(), os.homedir(), __dirname, and DNS server list, and reads the installer's /etc/passwd and /etc/hosts files, then POSTs the collected data over HTTPS to the hardcoded Burp Collaborator subdomain kqepxa9s4krgw7e7b6f7kufiy943stgi.oastify.com. The package name and behavior are consistent with a dependency-confusion reconnaissance beacon targeting internal build systems.

Source: amazon-inspector (42dcf2c659fc0c8b63b90671ae2a865a7811d5eeaaf321aab8355358117be47d)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.