mal-2026-16126

osv_npm
Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (4dbb0aa83cfffbdd408abb8f73299d5a47a0e9855c65b5940bb22112e0928d41) The package's postinstall lifecycle script (`node postinstall.js || true`) fires automatically on `npm install`. postinstall.js reads `os.hostname()`, embeds the sanitized value as a subdomain of the hardcoded host `1bdtwmd0wdrpwnlput1up9x39ufl3br0.oastify.com` (a Burp Collaborator out-of-band collector), and performs both a DNS lookup and a plain-HTTP GET to `/poc/<hostname>` at that host. The result is silent transmission of the installer's machine identifier to an attacker-controlled OOB endpoint on every install, with errors swallowed so the install does not visibly fail. The package name and version resemble a scoped Strapi plugin but the shipped payload performs no plugin functionality — only the beacon. ## Source: ossf-package-analysis (3dad65e846069addf34b62c3321a51ff2d43b04f6385c7edcbd8f3a2552e876b) The OpenSSF Package Analysis project identified 'strapi-plugin-vinsoc-1109' @ 3.6.8 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [
    {
      "database_specific": {
        "cwes": [
          {
            "cweId": "CWE-506",
            "description": "The product contains code that appears to be malicious in nature.",
            "name": "Embedded Malicious Code"
          }
        ],
        "indicators": {
          "evidence_files": [
            {
              "path": "postinstall.js",
              "sha256": "4edc34a17af8681465fa0cf95ad6543b56db5342533b358fb62ab0c834505ed5",
              "tlsh": "ec1102ee91f5e33096e033d49b8f01666796d3a18b488ed6945ec2958de143f13334be"
            },
            {
              "path": "package.json",
              "sha256": "0f7bf9f3cbb4cf090171269762b812a410915e43463c2fe9e3d089cdb867d1b3",
              "tlsh": "aff0a31c8915d53328c9db9e2833452d7a719d4b0456bf0c17d71184475c7b386bb64d"
            }
          ],
          "package_integrity": [
            {
              "filename": "strapi-plugin-vinsoc-1109-3.6.8.tgz",
              "hashes": {
                "sha1": "e6b41159840dcc5b4c3db294f9d6c1141a3a8af5",
                "sha512_sri": "sha512-t6LvEKqhGoetCEZ61Z/9t5vA86+T3p0sOMIP4y2SUdCf+s8hfspn7XGnc2xlev2DIMV87N9IIhGaEhcDivFtnw=="
              }
            }
          ]
        },
        "source": "https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/strapi-plugin-vinsoc-1109/MAL-2026-16126.json"
      },
      "package": {
        "ecosystem": "npm",
        "name": "strapi-plugin-vinsoc-1109",
        "purl": "pkg:npm/strapi-plugin-vinsoc-1109"
      },
      "versions": [
        "3.6.8"
      ]
    }
  ],
  "credits": [
    {
      "contact": [
        "inspector-research@amazon.com"
      ],
      "name": "Amazon Inspector",
      "type": "FINDER"
    },
    {
      "contact": [
        "https://github.com/ossf/package-analysis",
        "https://openssf.slack.com/channels/package_analysis"
      ],
      "name": "OpenSSF: Package Analysis",
      "type": "FINDER"
    }
  ],
  "database_specific": {
    "malicious-packages-origins": [
      {
        "import_time": "2026-09-11T08:24:21.278399507Z",
        "modified_time": "2026-09-11T07:51:51Z",
        "sha256": "3dad65e846069addf34b62c3321a51ff2d43b04f6385c7edcbd8f3a2552e876b",
        "source": "ossf-package-analysis",
        "versions": [
          "3.6.8"
        ]
      },
      {
        "id": "IN-MAL-2026-019994",
        "import_time": "2026-09-11T18:21:31.848181578Z",
        "modified_time": "2026-09-11T17:55:04Z",
        "sha256": "4dbb0aa83cfffbdd408abb8f73299d5a47a0e9855c65b5940bb22112e0928d41",
        "source": "amazon-inspector",
        "versions": [
          "3.6.8"
        ]
      }
    ]
  },
  "details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4dbb0aa83cfffbdd408abb8f73299d5a47a0e9855c65b5940bb22112e0928d41)\nThe package's postinstall lifecycle script (`node postinstall.js || true`) fires automatically on `npm install`. postinstall.js reads `os.hostname()`, embeds the sanitized value as a subdomain of the hardcoded host `1bdtwmd0wdrpwnlput1up9x39ufl3br0.oastify.com` (a Burp Collaborator out-of-band collector), and performs both a DNS lookup and a plain-HTTP GET to `/poc/<hostname>` at that host. The result is silent transmission of the installer's machine identifier to an attacker-controlled OOB endpoint on every install, with errors swallowed so the install does not visibly fail. The package name and version resemble a scoped Strapi plugin but the shipped payload performs no plugin functionality — only the beacon.\n\n## Source: ossf-package-analysis (3dad65e846069addf34b62c3321a51ff2d43b04f6385c7edcbd8f3a2552e876b)\nThe OpenSSF Package Analysis project identified 'strapi-plugin-vinsoc-1109' @ 3.6.8 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n",
  "id": "MAL-2026-16126",
  "modified": "2026-09-11T18:45:05.085799022Z",
  "published": "2026-09-11T07:51:51Z",
  "references": [
    {
      "type": "PACKAGE",
      "url": "https://www.npmjs.com/package/strapi-plugin-vinsoc-1109/v/3.6.8"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "Malicious code in strapi-plugin-vinsoc-1109 (npm)"
}
View JSON API Download JSON