Logo
npm

glia-functions-tools@1.2.1

Vulnerability report · Last retrieved from osv.dev September 9, 2026 at 4:09 AM UTC

Malicious

OSV ID

MAL-2026-12790

Ecosystem

npm

Summary

package.json's preinstall hook runs index.js, which collects hostname, username, home directory, DNS servers, and current working directory, reads /etc/passwd and /etc/hosts, and HTTPS-POSTs the JSON payload to a hardcoded Burp Collaborator (oastify.com) subdomain. The exfiltration fires automatically on npm install without any user interaction, and targets installer-side system identity and account data.

Source: amazon-inspector (e24f6c700225d22dcccdf1af7bb58c7628366ccc59b864431af5123909b42626)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.