MAL-2026-13549
Malicious code in dojo-rn-interview (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (42dcf2c659fc0c8b63b90671ae2a865a7811d5eeaaf321aab8355358117be47d) dojo-rn-interview@1.0.1 declares a preinstall script that runs index.js on `npm install`. The script collects host identifiers via os.hostname(), os.userInfo(), os.homedir(), __dirname, and DNS server list, and reads the installer's /etc/passwd and /etc/hosts files, then POSTs the collected data over HTTPS to the hardcoded Burp Collaborator subdomain kqepxa9s4krgw7e7b6f7kufiy943stgi.oastify.com. The package name and behavior are consistent with a dependency-confusion reconnaissance beacon targeting internal build systems.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dojo-rn-interview (npm). Pin to a known-safe version or switch to an alternative.