test890-auth@1.0.0
Vulnerability report · Last retrieved from osv.dev September 19, 2026 at 3:41 AM UTC
OSV ID
MAL-2026-16289
Ecosystem
npm
Summary
On npm install, index.js runs as a preinstall script and collects installer-side identifiers - home directory path, hostname, username, configured DNS servers, and the full contents of the consuming project's package.json - and POSTs them over HTTPS to the hardcoded out-of-band collector host wddbracmbzlaffkl9eivxzsvamgd43ss.oastify.com (Interactsh/Burp Collaborator). The package's own manifest additionally declares itself as a dependency (test890-auth ^1.0.0), matching a dependency-confusion probe shape aimed at internal registries. The package ships no functional code beyond the exfiltration beacon.
Source: amazon-inspector (a873f4ca1e603a5d6dc6d888de73a7f2c766a66af13f56a49538034e1e8706fd)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.