Malicious code in strapi-plugin-os-rec (npm)
MAL-2026-16234
Published · Modified
Dependency scanning
Check whether strapi-plugin-os-rec is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Description
__
Source: amazon-inspector (6b7f08345375bd52a25c34cc61a3e877c1a9f8f364a90a76b3a1eff55216ea03)
postinstall.js runs automatically on npm install and collects host reconnaissance data — os.hostname(), os.platform(), os.arch(), os.type(), os.release(), the current username, and enumeration of all network interface addresses — then transmits them as query-string parameters in an HTTP GET to hardcoded host 8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com on port 80 at path /osinfo. The oastify.com subdomain is a Burp Collaborator out-of-band interaction endpoint used to receive reconnaissance beacons. The behavior is undocumented, fires on default install with no user interaction, and identifies the installing machine to an attacker-controlled listener.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes