VDB
KO

MAL-2026-11152

Malicious code in tidal-embed-player (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (005d40bc86aa5e012bfb9a0cd23cf5de5c4d93b1f65880b2273b8708891fa7e5) package.json declares a preinstall hook that runs index.js on `npm install`. index.js collects host identifiers (os.hostname(), os.userInfo().username, homedir, DNS servers, cwd), reads the package.json, and reads /etc/passwd and /etc/hosts from the installer host, then POSTs the combined payload over HTTPS to 1rtlwocct2ruj1kc2njqbw96wx2qqhe6.oastify.com — a Burp Collaborator subdomain used to receive out-of-band callbacks. The package name suggests a Tidal media embed player but the shipped code performs only host reconnaissance and exfiltration, with no player functionality.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / tidal-embed-player

No fixed version published yet for tidal-embed-player (npm). Pin to a known-safe version or switch to an alternative.

References