app-sca-info-banking@0.0.24
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 10:33 AM UTC
OSV ID
MAL-2026-17182
Ecosystem
npm
Summary
package.json declares scripts.postinstall: node poc.js, causing poc.js to execute automatically on npm install. poc.js issues DNS (dns.resolve4) and HTTP (http.get) callbacks to unique subdomains under ki6rmdjnq5q8y7v8soxc080fz65ytohd.oastify.com (a Burp Suite Collaborator / OAST host) and writes a marker file under os.tmpdir(). The package's main entry is an empty stub (module.exports = {}); the postinstall payload is the package's only functionality. The DNS/HTTP callbacks to an attacker-controlled OAST domain confirm arbitrary code execution on the installer's host and leak install-event metadata to a third-party endpoint.
Source: amazon-inspector (9733b1d7500efca385ba6dc866f4ef1b04e0d1cd4ead564b9445551a2d72a51b)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.