strapi-plugin-osag@3.6.8
Malicious code in strapi-plugin-osag (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The postinstall hook (postinstall.js) runs automatically on install and collects host information — hostname, OS platform/arch/type/release, username, home directory, and all network interface IP addresses — then exfiltrates it via an HTTP GET request to the remote host 8y70jt07jkewju8wh0o1cgkaw12sqje8[.]oastify[.]com on port 80, path /osinfo, with the collected data encoded in the query string. The package is a Strapi plugin that performs no legitimate plugin function; its sole behaviour is this install-time host-metadata beacon.
- analyzed by
- Leitwacht
- first seen
- Sep 16, 2026, 10:53 AM
- analyzed
- Sep 16, 2026, 10:55 AM
Related advisories
- strapi-plugin-os-rec@3.6.8
- confx1789550882@1.0.0
- element-plus-vite-cli@2.9.3
- @asenfotech/unplugin-element-plus@2.9.3
- chai-as-agile@2.4.7
- @firelordzuka/pulse-poc@1.0.0
- tailwind-forms-styles@0.5.2
- csa-mfa@1.1.15
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.