VYPR

npm · Malicious package advisory

Malware

openai-pr-reviewer

GHSA-xr9x-fq9j-2f47

Malicious code in openai-pr-reviewer (npm)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (3553acd3c5abc3f71b55740c4b06b2eb278f81bb678c55211f2287a498b60b61)
The package's preinstall hook runs index.js, which collects the installer's hostname, username, home directory, DNS servers, current working directory, package.json contents, and the contents of /etc/passwd and /etc/hosts, then POSTs them over HTTPS to the hardcoded Burp Collaborator subdomain vjib8dmg59zuxwwymzboy0ymhdn4bvzk.oastify.com. Execution is automatic on npm install via the preinstall lifecycle script, with no user interaction required.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/72e5d8219b286d7332c4ad2364b87986138cf34c/osv/malicious/npm/openai-pr-reviewer/MAL-2026-14434.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/72e5d8219b286d7332c4ad2364b87986138cf34c/osv/malicious/npm/openai-pr-reviewer/MAL-2026-14434.json
- https://www.npmjs.com/package/openai-pr-reviewer/v/1.0.0
- https://github.com/advisories/GHSA-xr9x-fq9j-2f47

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.