Use of software with malware In dojo-rn-interview
Description
[email protected] declares a preinstall script that runs index.js on npm install. The script collects host identifiers via os.hostname(), os.userInfo(), os.homedir(), __dirname, and DNS server list, and reads the installer's /etc/passwd and /etc/hosts files, then POSTs the collected data over HTTPS to the hardcoded Burp Collaborator subdomain kqepxa9s4krgw7e7b6f7kufiy943stgi.oastify.com. The package name and behavior are consistent with a dependency-confusion reconnaissance beacon targeting internal build systems.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version |
|---|---|---|
npm |
Aliases
1. 2.