npm

jobber-app-template-react @1.0.1

Vulnerability report · Last retrieved from osv.dev July 28, 2026 at 4:33 PM UTC

Malicious

OSV ID

MAL-2026-11137

Ecosystem

npm

Summary

The package's preinstall hook runs index.js which fires automatically on npm install . The script collects host reconnaissance (os.hostname(), os.userInfo().username, home directory, DNS servers, __dirname) and reads the contents of /etc/passwd and /etc/hosts from the installer's machine, then HTTPS-POSTs a JSON payload to the hardcoded Burp Collaborator subdomain 5tzh3l2e1cetr1chf6osh4tg57b0zqnf.oastify.com. The behavior is unrelated to the package's advertised purpose as a React app template and is characteristic of a dependency-confusion exfiltration payload.

Source: amazon-inspector (844a2ac73b588b6c0c7c370dd647685768992ff3e6b5ef492e6fc6dc6be240ce)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.