npm

global-intel @1.0.1

Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 2:31 AM UTC

Malicious

OSV ID

MAL-2026-13952

Ecosystem

npm

Summary

package.json declares a preinstall hook that runs index.js on npm install . index.js collects host identity and OS files from the installer — os.hostname(), os.userInfo(), homedir, DNS server configuration, /etc/passwd, /etc/hosts, and package metadata — and HTTPS POSTs the payload to the hardcoded out-of-band host 0gh240ybp2rb80iyzrg4w2o3tuzlncb1.oastify.com (Burp Collaborator). The exfiltration fires automatically as a lifecycle side effect of installation with no user interaction.

Source: amazon-inspector (5449036ad6a1bf0ee192023ddb23ea7afefe53da7133ab91f4ffbc6d3253f5dc)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.