LWA-2026-12177 MAL-2026-16234 ↗ confirmed malware

strapi-plugin-os-rec@3.6.8

Malicious code in strapi-plugin-os-rec (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The postinstall hook (postinstall.js) runs automatically on install and collects host information — hostname, OS platform/arch/type/release, username, home directory, all network interface IP addresses, and the PATH/USER/HOME environment variables — then exfiltrates it as an HTTP GET query string to the remote host 8y70jt07jkewju8wh0o1cgkaw12sqje8[.]oastify[.]com on port 80 (path /osinfo). The package is a Strapi plugin that performs no plugin functionality; its only behaviour is this host-information beacon to an external endpoint.

analyzed by
Leitwacht
first seen
Sep 16, 2026, 10:50 AM
analyzed
Sep 16, 2026, 10:52 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.