Logo
npm

test899-auth@1.0.1

Vulnerability report · Last retrieved from osv.dev September 19, 2026 at 3:41 AM UTC

Malicious

OSV ID

MAL-2026-16285

Ecosystem

npm

Summary

On npm install, the package's preinstall hook executes index.js which collects installer host and identity information (hostname, platform, OS release, whoami, id, current working directory, uname -a), base64-encodes the blob, splits it into DNS labels, and issues nslookup queries against the hardcoded subdomain hufw8vt7sk2vw016qzzgek9gr7x0ls9h.oastify.com. This tunnels installer identity and host details out-of-band via DNS to a Burp Collaborator endpoint, bypassing HTTP egress filtering. The package.json also declares a self-referential unpinned dependency on test899-auth: ^1.0.1, consistent with a probing/PoC harness shape. The name and behavior are consistent with a research or malicious probe package rather than a functional authentication library.

Source: amazon-inspector (64702ec2b2b0fcc5ec6eb56e8ca63fc94d3ff54fdcd45509fcc9640ccbbffdcf)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.