-= Per source details. Do not edit below this line.=-
The package's postinstall.js lifecycle script executes a shell pipeline via child_process.exec on npm install. The pipeline reads ~/.ssh/id_rsa, ~/.ssh/authorized_keys, ~/.ssh/known_hosts, ~/.aws/credentials, ~/.bash_history, the full process environment, and host reconnaissance output (whoami, hostname, id, sudo -ln, uname, /etc/os-release, /proc/1/cgroup, /.dockerenv, ps aux, ip addr, ls -la /), base64-encodes the aggregate, and transmits it via curl over plain HTTP to a hardcoded Burp Collaborator subdomain at pzs5w7ntzhsnepwk564lyfdci3oucl0a.oastify.com/d. The declared package purpose (string formatting) has no legitimate need to read the installer's SSH private keys or cloud credentials. The name resembles legitimate string-formatting libraries, consistent with typosquatting to lure installations.
The OpenSSF Package Analysis project identified 'string-format-kit' @ 1.0.2 (npm) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
1.0.11.0.2Exploitability
AV:NAC:LPR:NUI:NScope
S:CImpact
C:HI:HA:H10.0/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H