VDB
KO

MAL-2026-14438

Malicious code in remove-bg-serverless-azure (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (dcbce8344eb0762c4a9ef029743efe13045422b839444b828c245a09a85fc74e) package.json declares `preinstall: node index.js`, so `npm install` automatically runs index.js. index.js reads os.hostname(), os.userInfo(), the user home directory, DNS server configuration, and the contents of /etc/passwd and /etc/hosts, and POSTs the collected data over HTTPS to the hardcoded host 7iqn7pls4ly6w8valba0xcxygpmha7yw.oastify.com (a Burp Collaborator / OAST subdomain used as an attacker-controlled callback). Installing the package causes installer-side identifiers and sensitive system files to be sent to an external attacker endpoint on install.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / remove-bg-serverless-azure

No fixed version published yet for remove-bg-serverless-azure (npm). Pin to a known-safe version or switch to an alternative.

References