VYPR

npm · Malicious package advisory

Malware

strapi-plugin-osag

GHSA-6jhp-v2xp-285p

Malicious code in strapi-plugin-osag (npm)

Details

**Severity:** Critical

**Affected versions:** `= 3.6.8`

## Source: amazon-inspector (34d9349a970008e54774fc533af589248d578e1d34f6f82a9a6630beeabd2203)
The package presents itself as a Strapi plugin but ships no plugin code — only a postinstall.js script that runs automatically on `npm install`. The script collects installer-side host identifiers (hostname, OS platform/arch/type/release, username, home directory) and enumerates all network interface addresses, then transmits them as query parameters in a plain HTTP GET to a hardcoded Burp Collaborator subdomain 8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com on port 80. The package's declared repository/homepage points at a placeholder github.com/user/strapi-plugin-yayccresh-meeb URL that does not identify a real publisher, and the Strapi-branded name does not match the shipped contents.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/77e1abe54c807a94ef54fde706a23385c94d9e9b/osv/malicious/npm/strapi-plugin-osag/MAL-2026-16235.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/77e1abe54c807a94ef54fde706a23385c94d9e9b/osv/malicious/npm/strapi-plugin-osag/MAL-2026-16235.json
- https://www.npmjs.com/package/strapi-plugin-osag/v/3.6.8
- https://github.com/advisories/GHSA-6jhp-v2xp-285p

Compromised versions (1)

  • = 3.6.8

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.