{"id":"MAL-2026-16234","summary":"Malicious code in strapi-plugin-os-rec (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6b7f08345375bd52a25c34cc61a3e877c1a9f8f364a90a76b3a1eff55216ea03)\npostinstall.js runs automatically on npm install and collects host reconnaissance data — os.hostname(), os.platform(), os.arch(), os.type(), os.release(), the current username, and enumeration of all network interface addresses — then transmits them as query-string parameters in an HTTP GET to hardcoded host 8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com on port 80 at path /osinfo. The oastify.com subdomain is a Burp Collaborator out-of-band interaction endpoint used to receive reconnaissance beacons. The behavior is undocumented, fires on default install with no user interaction, and identifies the installing machine to an attacker-controlled listener.\n","modified":"2026-09-16T14:30:07.158617673Z","published":"2026-09-16T13:59:37Z","database_specific":{"malicious-packages-origins":[{"sha256":"6b7f08345375bd52a25c34cc61a3e877c1a9f8f364a90a76b3a1eff55216ea03","source":"amazon-inspector","versions":["3.6.8"],"id":"IN-MAL-2026-020106","import_time":"2026-09-16T14:19:38.273138843Z","modified_time":"2026-09-16T13:59:37Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/strapi-plugin-os-rec/v/3.6.8"}],"affected":[{"package":{"name":"strapi-plugin-os-rec","ecosystem":"npm","purl":"pkg:npm/strapi-plugin-os-rec"},"versions":["3.6.8"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/strapi-plugin-os-rec/MAL-2026-16234.json","indicators":{"evidence_files":[{"sha256":"b8039024b8b547e13b3afc5b8eecaf38ba92f50b4b486f2a4bf9b5e7b740a720","tlsh":"a541ecd511ba666421b34ac5d59741214122e28a3e06f9fc3dec03e61fdaeecc2726f8","path":"postinstall.js"}],"package_integrity":[{"filename":"strapi-plugin-os-rec-3.6.8.tgz","hashes":{"sha512_sri":"sha512-t0j0Mt3omyqYyG3amYT7q0Y91PToNb8zP4isH0wrEsPEnw4MJp/cd0aCK/lvBt/o6Qp7H2WSQJlH+yGQPnQXWQ==","sha1":"2f00b60dc9ab0c53724bf11efd32a07650d20a40"}}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}