CRITICAL npm Malware

Malicious code in knowledge-grader (npm)

MAL-2026-12795

Published · Modified

Description


__

Source: amazon-inspector (74d01af74706eee07fb8ed306ec3b830641f63b4c055d605026edff65fd11c8f)

The package's preinstall hook runs index.js, which collects hostname, username, home directory, DNS servers, package path, and the contents of /etc/passwd and /etc/hosts, then HTTPS-POSTs the JSON payload to the hardcoded Burp Collaborator subdomain tebdjgz4guem6t74pf6iyowyjppgd71w.oastify.com. This fires automatically on npm install with no user interaction.

Ready to move

Start Securing

Free, no credit card | First findings in minutes