npm

triage_bot_using_sdkv3 @2.0.1

Vulnerability report · Last retrieved from osv.dev July 28, 2026 at 4:33 PM UTC

Malicious

OSV ID

MAL-2026-11153

Ecosystem

npm

Summary

package.json registers a preinstall hook that runs index.js on npm install. index.js collects os.hostname(), os.userInfo(), home directory, DNS server configuration, and reads /etc/passwd and /etc/hosts via fs.readFileSync, then HTTPS-POSTs the payload to the hardcoded Burp Collaborator subdomain mh7rhchf58lgymyr9wffhwfprgx7lx9m.oastify.com. Installing the package on a default npm install causes installer host identifiers and local account/host files to be transmitted to an out-of-band attacker-controlled endpoint.

Source: amazon-inspector (ed39efd544cae19da3ed546fecb2383729aef637bf623e00a9cf02f1f8ded05c)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.