logo

Database

Use of software with malware In dojo-rn-interview

Description

[email protected] declares a preinstall script that runs index.js on npm install. The script collects host identifiers via os.hostname(), os.userInfo(), os.homedir(), __dirname, and DNS server list, and reads the installer's /etc/passwd and /etc/hosts files, then POSTs the collected data over HTTPS to the hardcoded Burp Collaborator subdomain kqepxa9s4krgw7e7b6f7kufiy943stgi.oastify.com. The package name and behavior are consistent with a dependency-confusion reconnaissance beacon targeting internal build systems.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version