Malicious code in fundraiserservicepp (npm)
MAL-2026-11055
Published · Modified
Description
__
Source: amazon-inspector (6356b654b692d4c1222f3dc31dcfad683a6e193a41484d3c617c7c8d52db2313)
On npm install, the package's preinstall lifecycle executes index.js which collects os.hostname(), os.platform(), and os.arch() and POSTs them as JSON over HTTPS to the hardcoded subdomain rpke7za0zz1pwj9fz5058j0y5pbgz82wr.oastify.com — a Burp Collaborator out-of-band collector. The package provides no advertised functionality beyond this beacon and matches the dependency-confusion probe shape, with installer host identifiers leaving the machine automatically to a third-party OOB endpoint the installer did not opt into.
Source: ossf-package-analysis (cefb4588a67439c112176df4b9af71d40a1e2a12e0bf81ef200affa79e0cb0e0)
The OpenSSF Package Analysis project identified 'fundraiserservicepp' @ 1.5.0 (npm) as malicious.
It is considered malicious because:
- The package communicates with a domain associated with malicious activity.
Ready to move
Start Securing
Free, no credit card | First findings in minutes