LWA-2026-0074 MAL-2026-4265 ↗ confirmed malware

@asavie/i18n@99.0.3

Malicious code in @asavie/i18n (npm)

T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages

Analysis

On installation the package runs a preinstall hook that fingerprints the host, collecting the hostname and username via os.hostname() and os.userInfo(), and exfiltrates them through both DNS and HTTPS beacons to an out-of-band collaborator listener at oast[.]me. This is a dependency-confusion supply-chain payload that executes automatically during npm install.

analyzed by
Leitwacht
first seen
May 26, 2026, 07:02 PM
analyzed
May 26, 2026, 07:04 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.