VDB
EN

MAL-2026-14537

Malicious code in octopus-action (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (6968c2a12f60b671ee163f42c9da14ed51d9b0b29486b4a7d1bf5014b4c637f2) The package declares a preinstall lifecycle script (`node index.js`) that runs automatically on `npm install`. index.js collects the installer's hostname, OS username, home directory, configured DNS servers, package metadata, and the contents of /etc/passwd and /etc/hosts, then POSTs the payload over HTTPS to dfwvktnc563cparn1p88c8051w7ovej3.oastify.com, a Burp Collaborator out-of-band host controlled by a third party. Installing the package causes installer host identifiers and system files to be exfiltrated to that endpoint.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / octopus-action

No fixed version published yet for octopus-action (npm). Pin to a known-safe version or switch to an alternative.

참고