Logo
npm

@assetshop/verify-cli@99.0.1

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 6:41 AM UTC

Malicious

OSV ID

MAL-2026-13881

Ecosystem

npm

Summary

On npm install, the package's preinstall hook executes index.js, which collects installer identity and host information — whoami (via execSync), os.hostname(), os.platform(), os.arch(), process.cwd(), os.homedir(), and Node version — and transmits them to a hardcoded Interactsh/OAST callback subdomain at 5f8a1ed70fb7761d678agw9bapayyyyyb.oast.site via an HTTPS GET (with the collected values placed in the URL path) and a DNS lookup of ${user}.${hostname}.assetshop-verify-cli.<oast-host>. The package name in the @assetshop scope combined with the OAST beacon shape is the standard dependency-confusion reconnaissance pattern used to prove internal-name resolution against a private registry.

Source: amazon-inspector (7cace01fe47bda782a3a3af79a03154284b0e58f811cf19a63942a02aa5f7342)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.