Affected script: "install-scripts:preinstall"
The code is designed to collect sensitive information from the environment in which it's run, including the package name, current directory, home directory, hostname, username, DNS servers, and package.json content which might include custom metadata like private repository URLs (in the ___resolved
field) or other sensitive data. It then sends this collected data to an external server via an HTTPS POST request. The hostname "3785fe2ei87xo3195n4i7oo8lzrsfj38.oastify.com" suggests that it might be a server set up for receiving data from potentially compromised systems (as indicated by the pattern typically found with various 'out-of-band' interaction services like Burp Collaborator, Interactsh, or Pipedream). The use of these services is common in security testing or by attackers to detect and confirm external interactions, indicating this script could be used for malicious purposes such as data exfiltration.