VDB
Sign up

MAL-2026-16149

Malicious code in os-info-meeb322k (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (cf3b4f18f9d98ad0792f96d750aef64b390ae6a516d948457d1e78b1d3242ab8) The package's postinstall lifecycle script runs unconditionally on npm install. It collects host identifiers (hostname, platform, architecture, kernel release, uid/gid, CPU count, memory) and internal network interface addresses, base64-encodes the payload, and POSTs it over plain HTTP to the hardcoded subdomain vml73pdk3ft3t434ssjycv4khbn2btzi.oastify.com — a Burp Collaborator (OAST) callback host used to confirm code execution on the installer. The package has no other functionality; its sole install-time effect is the outbound beacon carrying installer reconnaissance data to an attacker-controlled domain.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/os-info-meeb322k

No fixed version published yet for os-info-meeb322k (npm). Pin to a known-safe version or switch to an alternative.

References