Logo
npm

test890-auth@1.0.0

Vulnerability report · Last retrieved from osv.dev September 19, 2026 at 3:41 AM UTC

Malicious

OSV ID

MAL-2026-16289

Ecosystem

npm

Summary

On npm install, index.js runs as a preinstall script and collects installer-side identifiers - home directory path, hostname, username, configured DNS servers, and the full contents of the consuming project's package.json - and POSTs them over HTTPS to the hardcoded out-of-band collector host wddbracmbzlaffkl9eivxzsvamgd43ss.oastify.com (Interactsh/Burp Collaborator). The package's own manifest additionally declares itself as a dependency (test890-auth ^1.0.0), matching a dependency-confusion probe shape aimed at internal registries. The package ships no functional code beyond the exfiltration beacon.

Source: amazon-inspector (a873f4ca1e603a5d6dc6d888de73a7f2c766a66af13f56a49538034e1e8706fd)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.