tool-registry-scripts@1.0.1
Vulnerability report · Last retrieved from osv.dev September 9, 2026 at 4:09 AM UTC
OSV ID
MAL-2026-12482
Ecosystem
npm
Summary
package.json declares a preinstall hook that runs index.js on npm install. index.js collects host identifiers (os.hostname(), os.userInfo(), homedir, DNS servers, cwd, package.json contents) and reads /etc/passwd and /etc/hosts, then POSTs the resulting JSON over HTTPS to the hardcoded out-of-band collaborator subdomain lsh5x8dwumsekllw37kacgaqxh3cr2fr.oastify.com. The destination is a Burp Collaborator OOB endpoint unrelated to any documented package purpose, and execution is automatic at install time.
Source: amazon-inspector (b635b8b6d257c079a0d0a9c06e37910b67f2e75d1e71dced264043624951ce06)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.