npm · Malicious package advisory
Malwarestrapi-plugin-vinsoc-1109
MAL-2026-16126
Malicious code in strapi-plugin-vinsoc-1109 (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (4dbb0aa83cfffbdd408abb8f73299d5a47a0e9855c65b5940bb22112e0928d41) The package's postinstall lifecycle script (`node postinstall.js || true`) fires automatically on `npm install`. postinstall.js reads `os.hostname()`, embeds the sanitized value as a subdomain of the hardcoded host `1bdtwmd0wdrpwnlput1up9x39ufl3br0.oastify.com` (a Burp Collaborator out-of-band collector), and performs both a DNS lookup and a plain-HTTP GET to `/poc/<hostname>` at that host. The result is silent transmission of the installer's machine identifier to an attacker-controlled OOB endpoint on every install, with errors swallowed so the install does not visibly fail. The package name and version resemble a scoped Strapi plugin but the shipped payload performs no plugin functionality — only the beacon. ## Source: ossf-package-analysis (3dad65e846069addf34b62c3321a51ff2d43b04f6385c7edcbd8f3a2552e876b) The OpenSSF Package Analysis project identified 'strapi-plugin-vinsoc-1109' @ 3.6.8 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
Compromised versions (1)
- 3.6.8
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.