npm

octopus-action @1.0.1

Vulnerability report · Last retrieved from osv.dev August 26, 2026 at 11:24 PM UTC

Malicious

OSV ID

MAL-2026-14537

Ecosystem

npm

Summary

The package declares a preinstall lifecycle script ( node index.js ) that runs automatically on npm install . index.js collects the installer's hostname, OS username, home directory, configured DNS servers, package metadata, and the contents of /etc/passwd and /etc/hosts, then POSTs the payload over HTTPS to dfwvktnc563cparn1p88c8051w7ovej3.oastify.com, a Burp Collaborator out-of-band host controlled by a third party. Installing the package causes installer host identifiers and system files to be exfiltrated to that endpoint.

Source: amazon-inspector (6968c2a12f60b671ee163f42c9da14ed51d9b0b29486b4a7d1bf5014b4c637f2)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.