Logo
npm

strapi-plugin-osag@3.6.8

Vulnerability report · Last retrieved from osv.dev September 16, 2026 at 3:29 PM UTC

Malicious

OSV ID

MAL-2026-16235

Ecosystem

npm

Summary

The package presents itself as a Strapi plugin but ships no plugin code — only a postinstall.js script that runs automatically on npm install. The script collects installer-side host identifiers (hostname, OS platform/arch/type/release, username, home directory) and enumerates all network interface addresses, then transmits them as query parameters in a plain HTTP GET to a hardcoded Burp Collaborator subdomain 8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com on port 80. The package's declared repository/homepage points at a placeholder github.com/user/strapi-plugin-yayccresh-meeb URL that does not identify a real publisher, and the Strapi-branded name does not match the shipped contents.

Source: amazon-inspector (34d9349a970008e54774fc533af589248d578e1d34f6f82a9a6630beeabd2203)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.