npm

knowledge-grader @1.0.1

Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC

Malicious

OSV ID

MAL-2026-12795

Ecosystem

npm

Summary

The package's preinstall hook runs index.js, which collects hostname, username, home directory, DNS servers, package path, and the contents of /etc/passwd and /etc/hosts, then HTTPS-POSTs the JSON payload to the hardcoded Burp Collaborator subdomain tebdjgz4guem6t74pf6iyowyjppgd71w.oastify.com. This fires automatically on npm install with no user interaction.

Source: amazon-inspector (74d01af74706eee07fb8ed306ec3b830641f63b4c055d605026edff65fd11c8f)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.