MAL-2026-14536
Malicious code in mt-ts-serverless-starter (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (53da5b8989180a10122e1e8ab801ab76dc7587761bb58d05377359b8f8e09d52) package.json declares a preinstall hook that runs `node index.js` on every `npm install`. index.js collects installer host identity and system files — os.hostname(), os.userInfo(), home directory, DNS server configuration, /etc/passwd, /etc/hosts, and the full package.json — and HTTPS POSTs the payload to the hardcoded Burp Collaborator subdomain e4jw9ucdu7sdebgoqqx919p6qxwoke83.oastify.com. The exfiltration fires unconditionally at install time with no user interaction.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for mt-ts-serverless-starter (npm). Pin to a known-safe version or switch to an alternative.