Logo
npm

os-info-meeb322k@1.0.0

Vulnerability report · Last retrieved from osv.dev September 15, 2026 at 4:24 AM UTC

Malicious

OSV ID

MAL-2026-16149

Ecosystem

npm

Summary

The package's postinstall lifecycle script runs unconditionally on npm install. It collects host identifiers (hostname, platform, architecture, kernel release, uid/gid, CPU count, memory) and internal network interface addresses, base64-encodes the payload, and POSTs it over plain HTTP to the hardcoded subdomain vml73pdk3ft3t434ssjycv4khbn2btzi.oastify.com — a Burp Collaborator (OAST) callback host used to confirm code execution on the installer. The package has no other functionality; its sole install-time effect is the outbound beacon carrying installer reconnaissance data to an attacker-controlled domain.

Source: amazon-inspector (cf3b4f18f9d98ad0792f96d750aef64b390ae6a516d948457d1e78b1d3242ab8)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.