MAL-2026-16235
Malicious code in strapi-plugin-osag (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (34d9349a970008e54774fc533af589248d578e1d34f6f82a9a6630beeabd2203) The package presents itself as a Strapi plugin but ships no plugin code — only a postinstall.js script that runs automatically on `npm install`. The script collects installer-side host identifiers (hostname, OS platform/arch/type/release, username, home directory) and enumerates all network interface addresses, then transmits them as query parameters in a plain HTTP GET to a hardcoded Burp Collaborator subdomain 8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com on port 80. The package's declared repository/homepage points at a placeholder github.com/user/strapi-plugin-yayccresh-meeb URL that does not identify a real publisher, and the Strapi-branded name does not match the shipped contents.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for strapi-plugin-osag (npm). Pin to a known-safe version or switch to an alternative.