@asavie/i18n@99.0.3
Malicious code in @asavie/i18n (npm)
T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages
Analysis
On installation the package runs a preinstall hook that fingerprints the host, collecting the hostname and username via os.hostname() and os.userInfo(), and exfiltrates them through both DNS and HTTPS beacons to an out-of-band collaborator listener at oast[.]me. This is a dependency-confusion supply-chain payload that executes automatically during npm install.
- analyzed by
- Leitwacht
- first seen
- May 26, 2026, 07:02 PM
- analyzed
- May 26, 2026, 07:04 PM
Related advisories
- forge-jsxy@1.0.91
- swiper_angular@5.9999.0
- fundraiserserv@28.0.0
- preferenceslifecycle-paypal@28.0.0
- client-cookies-agent@99.9.7
- @wagni_bot/pumpfun-sdk@1.2.0
- @wagni_bot/solana-sdk@1.2.0
- @wagni_bot/orca-sdk@1.2.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.