Logo
npm

with-cte@1.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 8:28 PM UTC

Malicious

OSV ID

MAL-2026-17579

Ecosystem

npm

Summary

The package declares a preinstall lifecycle hook (preinstall: node index.js) that runs automatically on npm install. index.js collects installer host identifiers (os.hostname, os.userInfo, homedir, DNS servers) and reads the contents of /etc/passwd and /etc/hosts, then POSTs the collected data over HTTPS to the Burp Collaborator subdomain 187d714jo62z5j5c39hc437myd44sxgm.oastify.com. The package otherwise contains no library code, has empty author/description metadata, and provides no functionality — the shipped surface is solely the install-time beacon, consistent with a dependency-confusion or internal-name squat probe.

Source: amazon-inspector (8eceeb0a05cd8d1a289f1a1006df8acd825d73f341ec1a50e095dc2850b866c8)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.