CRITICAL npm Malware
Malicious code in knowledge-grader (npm)
MAL-2026-12795
Published · Modified
Description
__
Source: amazon-inspector (74d01af74706eee07fb8ed306ec3b830641f63b4c055d605026edff65fd11c8f)
The package's preinstall hook runs index.js, which collects hostname, username, home directory, DNS servers, package path, and the contents of /etc/passwd and /etc/hosts, then HTTPS-POSTs the JSON payload to the hardcoded Burp Collaborator subdomain tebdjgz4guem6t74pf6iyowyjppgd71w.oastify.com. This fires automatically on npm install with no user interaction.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes