VYPR

npm · Malicious package advisory

Malware

strapi-plugin-osag

MAL-2026-16235

Malicious code in strapi-plugin-osag (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (34d9349a970008e54774fc533af589248d578e1d34f6f82a9a6630beeabd2203)
The package presents itself as a Strapi plugin but ships no plugin code — only a postinstall.js script that runs automatically on `npm install`. The script collects installer-side host identifiers (hostname, OS platform/arch/type/release, username, home directory) and enumerates all network interface addresses, then transmits them as query parameters in a plain HTTP GET to a hardcoded Burp Collaborator subdomain 8y70jt07jkewju8wh0o1cgkaw12sqje8.oastify.com on port 80. The package's declared repository/homepage points at a placeholder github.com/user/strapi-plugin-yayccresh-meeb URL that does not identify a real publisher, and the Strapi-branded name does not match the shipped contents.

Compromised versions (1)

  • 3.6.8

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.