Malicious code in fundraiserservpp (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (0bca913238607a18079a675e2fe652c25c04c2bbc62f5c577bb2b6d2424cd4a8) [email protected] runs `node index.js` as a `preinstall` lifecycle script on `npm install`. The script collects host metadata from the installer machine — `os.hostname()`, `os.platform()`, `os.arch()`, the user home directory path, and configured DNS servers — and issues an HTTPS POST to a hardcoded Burp Collaborator subdomain (`mrh99ucv1u3kyeba1020ae2t7kdc12pr.oastify.com/hit`) with that data as a JSON body. The beacon fires automatically at install time with no user interaction. The destination is an attacker-controlled out-of-band interaction endpoint typical of dependency-confusion reconnaissance, confirming to the operator that the package name was successfully resolved and installed inside a target build environment.
AI Analysis
Technical Summary
The fundraiserservpp npm package version 1.9.0 includes a preinstall script that executes index.js on npm install. This script gathers environment information such as hostname, platform, architecture, home directory, and configured DNS servers using the Node.js os module. It then sends this information as JSON to a Burp Collaborator subdomain, an out-of-band callback server used to confirm code execution and enumerate victim environments. This behavior is consistent with reconnaissance activity in dependency confusion attacks, allowing attackers to collect data about the victim system automatically during package installation.
Potential Impact
The malicious code leaks sensitive environment information from the victim's machine to an external attacker-controlled server without user consent. This can aid attackers in profiling the victim environment for further targeted attacks or exploitation. While no direct code execution beyond the preinstall script is described, the unauthorized data exfiltration represents a privacy and security risk.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid installing version 1.9.0 of fundraiserservpp. Verify package integrity and source before installation. Monitor for updates or advisories from the package maintainer or npm registry regarding this issue. Consider using package auditing tools to detect malicious scripts in dependencies.
Malicious code in fundraiserservpp (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (0bca913238607a18079a675e2fe652c25c04c2bbc62f5c577bb2b6d2424cd4a8) [email protected] runs `node index.js` as a `preinstall` lifecycle script on `npm install`. The script collects host metadata from the installer machine — `os.hostname()`, `os.platform()`, `os.arch()`, the user home directory path, and configured DNS servers — and issues an HTTPS POST to a hardcoded Burp Collaborator subdomain (`mrh99ucv1u3kyeba1020ae2t7kdc12pr.oastify.com/hit`) with that data as a JSON body. The beacon fires automatically at install time with no user interaction. The destination is an attacker-controlled out-of-band interaction endpoint typical of dependency-confusion reconnaissance, confirming to the operator that the package name was successfully resolved and installed inside a target build environment.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The fundraiserservpp npm package version 1.9.0 includes a preinstall script that executes index.js on npm install. This script gathers environment information such as hostname, platform, architecture, home directory, and configured DNS servers using the Node.js os module. It then sends this information as JSON to a Burp Collaborator subdomain, an out-of-band callback server used to confirm code execution and enumerate victim environments. This behavior is consistent with reconnaissance activity in dependency confusion attacks, allowing attackers to collect data about the victim system automatically during package installation.
Potential Impact
The malicious code leaks sensitive environment information from the victim's machine to an external attacker-controlled server without user consent. This can aid attackers in profiling the victim environment for further targeted attacks or exploitation. While no direct code execution beyond the preinstall script is described, the unauthorized data exfiltration represents a privacy and security risk.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid installing version 1.9.0 of fundraiserservpp. Verify package integrity and source before installation. Monitor for updates or advisories from the package maintainer or npm registry regarding this issue. Consider using package auditing tools to detect malicious scripts in dependencies.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12386
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a735743bf8831d539159c6b
Added to database: 08/05/2026, 15:31:15 UTC
Last enriched: 08/05/2026, 17:18:46 UTC
Last updated: 09/07/2026, 22:02:54 UTC
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.