npm

fundraiserservpp @1.9.0

Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC

Malicious

OSV ID

MAL-2026-12386

Ecosystem

npm

Summary

fundraiserservpp@2.0.0 runs node index.js as a preinstall lifecycle script on npm install . The script collects host metadata from the installer machine — os.hostname() , os.platform() , os.arch() , the user home directory path, and configured DNS servers — and issues an HTTPS POST to a hardcoded Burp Collaborator subdomain ( mrh99ucv1u3kyeba1020ae2t7kdc12pr.oastify.com/hit ) with that data as a JSON body. The beacon fires automatically at install time with no user interaction. The destination is an attacker-controlled out-of-band interaction endpoint typical of dependency-confusion reconnaissance, confirming to the operator that the package name was successfully resolved and installed inside a target build environment.

Source: amazon-inspector (0bca913238607a18079a675e2fe652c25c04c2bbc62f5c577bb2b6d2424cd4a8)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.