tool-registry-scripts @1.0.0
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC
OSV ID
MAL-2026-12482
Ecosystem
npm
Summary
package.json declares a preinstall hook that runs index.js on npm install . index.js collects host identifiers (os.hostname(), os.userInfo(), homedir, DNS servers, cwd, package.json contents) and reads /etc/passwd and /etc/hosts, then POSTs the resulting JSON over HTTPS to the hardcoded out-of-band collaborator subdomain lsh5x8dwumsekllw37kacgaqxh3cr2fr.oastify.com. The destination is a Burp Collaborator OOB endpoint unrelated to any documented package purpose, and execution is automatic at install time.
Source: amazon-inspector (b635b8b6d257c079a0d0a9c06e37910b67f2e75d1e71dced264043624951ce06)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.