github-app-sts-action @1.0.1
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC
OSV ID
MAL-2026-12389
Ecosystem
npm
Summary
The package declares a preinstall lifecycle hook that runs index.js on npm install . index.js collects host identifiers and system files (os.hostname(), os.userInfo(), home directory, DNS servers, /etc/passwd, /etc/hosts, and package.json contents) and POSTs them via HTTPS to the hardcoded subdomain lncqub6t1loht8b887c8hvcjva13ptdi.oastify.com — a Burp Collaborator out-of-band interaction host used for reconnaissance. There is no advertised functional purpose in the package that would justify this data collection; the code path exists solely to transmit installer host and credential-adjacent file contents to an attacker-controlled endpoint.
Source: amazon-inspector (9434f2e4ac17da4d2b9dff0c36ed8b3c5cc3f76882b9898b768e78ba982bbac2)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.