CRITICAL npm Malware

Malicious code in strapi-plugin-os-rec (npm)

MAL-2026-16234

Published · Modified

Dependency scanning

Check whether strapi-plugin-os-rec is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Description


__

Source: amazon-inspector (6b7f08345375bd52a25c34cc61a3e877c1a9f8f364a90a76b3a1eff55216ea03)

postinstall.js runs automatically on npm install and collects host reconnaissance data — os.hostname(), os.platform(), os.arch(), os.type(), os.release(), the current username, and enumeration of all network interface addresses — then transmits them as query-string parameters in an HTTP GET to hardcoded host 8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com on port 80 at path /osinfo. The oastify.com subdomain is a Burp Collaborator out-of-band interaction endpoint used to receive reconnaissance beacons. The behavior is undocumented, fires on default install with no user interaction, and identifies the installing machine to an attacker-controlled listener.

Ready to move

Start Securing

Free, no credit card | First findings in minutes