npm

identityauthorizationserv @28.0.0

Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 1:58 AM UTC

Malicious

OSV ID

MAL-2026-11100

Ecosystem

npm

Summary

identityauthorizationserv@28.0.0 wires scripts.preinstall to node index.js, so on npm install the package auto-executes code that collects host reconnaissance data (os.hostname(), os.platform(), os.arch(), os.homedir(), and dns.getServers()) and POSTs it to a hardcoded out-of-band callback host at lwl8ethu6t8j3dg96z7zfd7scjib68ux.oastify.com/hit. oastify.com is Burp Collaborator infrastructure used for OOB exfiltration in dependency-confusion probes; the destination is attacker-controlled and unrelated to any legitimate publisher. The package self-describes as a dependency-confusion proof of concept, and the name pattern is consistent with a squat targeting an internal package name.

Source: amazon-inspector (ca4808d7fab80b2202538cad6c5a1be4d62eb973ac35eb3a431fdf33f68b67ee)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.