MAL-2026-16149
Malicious code in os-info-meeb322k (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (cf3b4f18f9d98ad0792f96d750aef64b390ae6a516d948457d1e78b1d3242ab8) The package's postinstall lifecycle script runs unconditionally on npm install. It collects host identifiers (hostname, platform, architecture, kernel release, uid/gid, CPU count, memory) and internal network interface addresses, base64-encodes the payload, and POSTs it over plain HTTP to the hardcoded subdomain vml73pdk3ft3t434ssjycv4khbn2btzi.oastify.com — a Burp Collaborator (OAST) callback host used to confirm code execution on the installer. The package has no other functionality; its sole install-time effect is the outbound beacon carrying installer reconnaissance data to an attacker-controlled domain.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for os-info-meeb322k (npm). Pin to a known-safe version or switch to an alternative.