VDB
Sign up

MAL-2026-16152

Malicious code in strapi-plugin-os-info-meeb322k (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (26da05bb07f15b53c17000d82631f739bcbfed9c94b9b4174e1c3cb769049ce5) The package declares a postinstall script (postinstall.js) that runs automatically on `npm install`. The script collects host reconnaissance data — os.hostname(), os.platform(), kernel release, uid/gid, all network interface addresses, memory and CPU info — base64-encodes the JSON payload, and POSTs it over plain HTTP to the hardcoded out-of-band host vml73pdk3ft3t434ssjycv4khbn2btzi.oastify.com (a Burp Collaborator subdomain). The package name mimics strapi-plugin-os-info but has no legitimate plugin functionality; the only shipped behavior is the install-time beacon to an attacker-controlled OOB interaction endpoint.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/strapi-plugin-os-info-meeb322k

No fixed version published yet for strapi-plugin-os-info-meeb322k (npm). Pin to a known-safe version or switch to an alternative.

References