{"id":"MAL-2026-16235","summary":"Malicious code in strapi-plugin-osag (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (34d9349a970008e54774fc533af589248d578e1d34f6f82a9a6630beeabd2203)\nThe package presents itself as a Strapi plugin but ships no plugin code — only a postinstall.js script that runs automatically on `npm install`. The script collects installer-side host identifiers (hostname, OS platform/arch/type/release, username, home directory) and enumerates all network interface addresses, then transmits them as query parameters in a plain HTTP GET to a hardcoded Burp Collaborator subdomain 8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com on port 80. The package's declared repository/homepage points at a placeholder github.com/user/strapi-plugin-yayccresh-meeb URL that does not identify a real publisher, and the Strapi-branded name does not match the shipped contents.\n","modified":"2026-09-16T14:30:06.829444122Z","published":"2026-09-16T13:59:21Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-09-16T14:19:38.166654663Z","modified_time":"2026-09-16T13:59:21Z","sha256":"34d9349a970008e54774fc533af589248d578e1d34f6f82a9a6630beeabd2203","source":"amazon-inspector","versions":["3.6.8"],"id":"IN-MAL-2026-020104"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/strapi-plugin-osag/v/3.6.8"}],"affected":[{"package":{"name":"strapi-plugin-osag","ecosystem":"npm","purl":"pkg:npm/strapi-plugin-osag"},"versions":["3.6.8"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"strapi-plugin-osag-3.6.8.tgz","hashes":{"sha1":"94fc7bdcfd5a3c02205f216cf027947ba048cd5a","sha512_sri":"sha512-eTHA7KgrwRmRnCV8Ke/gAoQfGAdS/T+bhnFQUKLBG/2Q8czY1VMTp8DD37aCb90b29fhXlx7bcxFzajmD5PFHw=="}}],"evidence_files":[{"tlsh":"17511fd511ba666421b345c5d59741214122d28a3e02f8fc3dec03e71fdaeecc1726f8","path":"postinstall.js","sha256":"f02e07cef3bdbc71d060b091eab1f15c4bb4ea89ff12e41a0073261f00c98c25"},{"sha256":"791367c76fd96690863754e4e1376546c153514e55a7835d6df86b4c50d0c8c8","tlsh":"acf04966ca2455a32dec3a94a81a1186a72a4e478c81fc1d23b3011c8f0e2e7747f5dd","path":"package.json"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/strapi-plugin-osag/MAL-2026-16235.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}