@asavie/i18n@99.0.3
Malicious code in @asavie/i18n (npm)
T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages
Analysis
On installation the package runs a preinstall hook that fingerprints the host, collecting the hostname and username via os.hostname() and os.userInfo(), and exfiltrates them through both DNS and HTTPS beacons to an out-of-band collaborator listener at oast[.]me. This is a dependency-confusion supply-chain payload that executes automatically during npm install.
- analyzed by
- Leitwacht
- first seen
- May 26, 2026, 07:02 PM
- analyzed
- May 26, 2026, 07:04 PM
Related advisories
- forge-jsxy@1.0.91
- eslint-plugin-vitest-ts@1.0.4
- fundraiserserv@28.0.0
- relativity-pdfjs-dist@99.9.9
- client-cookies-agent@99.9.7
- @wagni_bot/pumpfun-sdk@1.2.0
- @wagni_bot/solana-sdk@1.2.0
- @playerdata-internal/playerdata-core@9999.99.20
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.