VYPR

npm · Malicious package advisory

Malware

strapi-plugin-vinsoc-1109

MAL-2026-16126

Malicious code in strapi-plugin-vinsoc-1109 (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (4dbb0aa83cfffbdd408abb8f73299d5a47a0e9855c65b5940bb22112e0928d41)
The package's postinstall lifecycle script (`node postinstall.js || true`) fires automatically on `npm install`. postinstall.js reads `os.hostname()`, embeds the sanitized value as a subdomain of the hardcoded host `1bdtwmd0wdrpwnlput1up9x39ufl3br0.oastify.com` (a Burp Collaborator out-of-band collector), and performs both a DNS lookup and a plain-HTTP GET to `/poc/<hostname>` at that host. The result is silent transmission of the installer's machine identifier to an attacker-controlled OOB endpoint on every install, with errors swallowed so the install does not visibly fail. The package name and version resemble a scoped Strapi plugin but the shipped payload performs no plugin functionality — only the beacon.

## Source: ossf-package-analysis (3dad65e846069addf34b62c3321a51ff2d43b04f6385c7edcbd8f3a2552e876b)
The OpenSSF Package Analysis project identified 'strapi-plugin-vinsoc-1109' @ 3.6.8 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

Compromised versions (1)

  • 3.6.8

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.