npm · Malicious package advisory
Malwareopenai-pr-reviewer
MAL-2026-14434
Malicious code in openai-pr-reviewer (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (3553acd3c5abc3f71b55740c4b06b2eb278f81bb678c55211f2287a498b60b61) The package's preinstall hook runs index.js, which collects the installer's hostname, username, home directory, DNS servers, current working directory, package.json contents, and the contents of /etc/passwd and /etc/hosts, then POSTs them over HTTPS to the hardcoded Burp Collaborator subdomain vjib8dmg59zuxwwymzboy0ymhdn4bvzk.oastify.com. Execution is automatic on npm install via the preinstall lifecycle script, with no user interaction required.
Compromised versions (1)
- 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.