-= Per source details. Do not edit below this line.=-
package.json declares a postinstall hook that runs index.js on npm install. index.js collects host identifiers (os.hostname(), os.userInfo(), os.platform(), OS release) and enriches them with public IP (via ipify) and geo/ISP (via ipapi.co), then POSTs the JSON payload to a hardcoded Burp Collaborator subdomain at https://dq7q2vt6l79ouvgyzavan3w2rtxkp8gw5.oastify.com/callback. The package self-describes as a dependency-confusion takeover PoC; the beacon fires automatically on install without user interaction.
The OpenSSF Package Analysis project identified 'subapp-pkg-util' @ 99.0.1 (npm) as malicious.
It is considered malicious because:
99.0.1Exploitability
AV:NAC:LPR:NUI:NScope
S:CImpact
C:HI:HA:H10.0/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H