global-intel @1.0.1
Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 2:31 AM UTC
OSV ID
MAL-2026-13952
Ecosystem
npm
Summary
package.json declares a preinstall hook that runs index.js on npm install . index.js collects host identity and OS files from the installer — os.hostname(), os.userInfo(), homedir, DNS server configuration, /etc/passwd, /etc/hosts, and package metadata — and HTTPS POSTs the payload to the hardcoded out-of-band host 0gh240ybp2rb80iyzrg4w2o3tuzlncb1.oastify.com (Burp Collaborator). The exfiltration fires automatically as a lifecycle side effect of installation with no user interaction.
Source: amazon-inspector (5449036ad6a1bf0ee192023ddb23ea7afefe53da7133ab91f4ffbc6d3253f5dc)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.