—
MAL-2026-12795
Malicious code in knowledge-grader (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (74d01af74706eee07fb8ed306ec3b830641f63b4c055d605026edff65fd11c8f) The package's preinstall hook runs index.js, which collects hostname, username, home directory, DNS servers, package path, and the contents of /etc/passwd and /etc/hosts, then HTTPS-POSTs the JSON payload to the hardcoded Burp Collaborator subdomain tebdjgz4guem6t74pf6iyowyjppgd71w.oastify.com. This fires automatically on npm install with no user interaction.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm / knowledge-grader
No fixed version published yet for knowledge-grader (npm). Pin to a known-safe version or switch to an alternative.