xo-twofa @28.0.0
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 1:58 AM UTC
OSV ID
MAL-2026-11105
Ecosystem
npm
Summary
package.json declares a preinstall script that runs node index.js on npm install . index.js collects host identifiers (os.hostname(), os.platform(), os.arch(), os.homedir(), dns.getServers()) and POSTs them as JSON to the hardcoded host f4k2mnpoengdb7o3etftn7fmkdq5ew5ku.oastify.com (a Burp Collaborator out-of-band interaction endpoint). The beacon fires automatically on install without user interaction and self-describes as a dependency-confusion proof of concept.
Source: amazon-inspector (47761909a1686ad1db2239f5055c8526e38ac88c07060c886157d157d15b4315)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.