octopus-action @1.0.1
Vulnerability report · Last retrieved from osv.dev August 26, 2026 at 11:24 PM UTC
OSV ID
MAL-2026-14537
Ecosystem
npm
Summary
The package declares a preinstall lifecycle script ( node index.js ) that runs automatically on npm install . index.js collects the installer's hostname, OS username, home directory, configured DNS servers, package metadata, and the contents of /etc/passwd and /etc/hosts, then POSTs the payload over HTTPS to dfwvktnc563cparn1p88c8051w7ovej3.oastify.com, a Burp Collaborator out-of-band host controlled by a third party. Installing the package causes installer host identifiers and system files to be exfiltrated to that endpoint.
Source: amazon-inspector (6968c2a12f60b671ee163f42c9da14ed51d9b0b29486b4a7d1bf5014b4c637f2)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.