octopus-action@1.1.1
Vulnerability report · Last retrieved from osv.dev September 9, 2026 at 4:09 AM UTC
OSV ID
MAL-2026-14537
Ecosystem
npm
Summary
The package declares a preinstall lifecycle script (node index.js) that runs automatically on npm install. index.js collects the installer's hostname, OS username, home directory, configured DNS servers, package metadata, and the contents of /etc/passwd and /etc/hosts, then POSTs the payload over HTTPS to dfwvktnc563cparn1p88c8051w7ovej3.oastify.com, a Burp Collaborator out-of-band host controlled by a third party. Installing the package causes installer host identifiers and system files to be exfiltrated to that endpoint.
Source: amazon-inspector (6968c2a12f60b671ee163f42c9da14ed51d9b0b29486b4a7d1bf5014b4c637f2)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.