strapi-plugin-vinsoc-1109@3.6.8
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 9:32 AM UTC
OSV ID
MAL-2026-16126
Ecosystem
npm
Summary
The package's postinstall lifecycle script (node postinstall.js || true) fires automatically on npm install. postinstall.js reads os.hostname(), embeds the sanitized value as a subdomain of the hardcoded host 1bdtwmd0wdrpwnlput1up9x39ufl3br0.oastify.com (a Burp Collaborator out-of-band collector), and performs both a DNS lookup and a plain-HTTP GET to /poc/<hostname> at that host. The result is silent transmission of the installer's machine identifier to an attacker-controlled OOB endpoint on every install, with errors swallowed so the install does not visibly fail. The package name and version resemble a scoped Strapi plugin but the shipped payload performs no plugin functionality — only the beacon.
Source: amazon-inspector (4dbb0aa83cfffbdd408abb8f73299d5a47a0e9855c65b5940bb22112e0928d41)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.