LWA-2026-10099 MAL-2026-12794 ↗ confirmed malware

karapace-docs@1.0.1

Malicious code in karapace-docs (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package's preinstall hook (node index.js) runs automatically on install and exfiltrates host reconnaissance data to an attacker-controlled Burp Collaborator endpoint. It collects the hostname, current username, home directory, DNS server addresses, the full package.json, and the complete contents of /etc/passwd and /etc/hosts, then POSTs them as a JSON body over HTTPS to n6usddpvkn7jcauar9va0xvleck48uwj[.]oastify[.]com:443 (path /). The package is a minimal two-file stub with no legitimate functionality.

analyzed by
Leitwacht
first seen
Aug 5, 2026, 09:16 AM
analyzed
Aug 5, 2026, 09:21 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.