test899-auth@1.0.1
Vulnerability report · Last retrieved from osv.dev September 19, 2026 at 3:41 AM UTC
OSV ID
MAL-2026-16285
Ecosystem
npm
Summary
On npm install, the package's preinstall hook executes index.js which collects installer host and identity information (hostname, platform, OS release, whoami, id, current working directory, uname -a), base64-encodes the blob, splits it into DNS labels, and issues nslookup queries against the hardcoded subdomain hufw8vt7sk2vw016qzzgek9gr7x0ls9h.oastify.com. This tunnels installer identity and host details out-of-band via DNS to a Burp Collaborator endpoint, bypassing HTTP egress filtering. The package.json also declares a self-referential unpinned dependency on test899-auth: ^1.0.1, consistent with a probing/PoC harness shape. The name and behavior are consistent with a research or malicious probe package rather than a functional authentication library.
Source: amazon-inspector (64702ec2b2b0fcc5ec6eb56e8ca63fc94d3ff54fdcd45509fcc9640ccbbffdcf)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.