Logo
npm

strapi-plugin-os-info-meeb322k@3.6.8

Vulnerability report · Last retrieved from osv.dev September 15, 2026 at 4:24 AM UTC

Malicious

OSV ID

MAL-2026-16152

Ecosystem

npm

Summary

The package declares a postinstall script (postinstall.js) that runs automatically on npm install. The script collects host reconnaissance data — os.hostname(), os.platform(), kernel release, uid/gid, all network interface addresses, memory and CPU info — base64-encodes the JSON payload, and POSTs it over plain HTTP to the hardcoded out-of-band host vml73pdk3ft3t434ssjycv4khbn2btzi.oastify.com (a Burp Collaborator subdomain). The package name mimics strapi-plugin-os-info but has no legitimate plugin functionality; the only shipped behavior is the install-time beacon to an attacker-controlled OOB interaction endpoint.

Source: amazon-inspector (26da05bb07f15b53c17000d82631f739bcbfed9c94b9b4174e1c3cb769049ce5)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.