karapace-docs@1.0.1
Malicious code in karapace-docs (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The package's preinstall hook (node index.js) runs automatically on install and exfiltrates host reconnaissance data to an attacker-controlled Burp Collaborator endpoint. It collects the hostname, current username, home directory, DNS server addresses, the full package.json, and the complete contents of /etc/passwd and /etc/hosts, then POSTs them as a JSON body over HTTPS to n6usddpvkn7jcauar9va0xvleck48uwj[.]oastify[.]com:443 (path /). The package is a minimal two-file stub with no legitimate functionality.
- analyzed by
- Leitwacht
- first seen
- Aug 5, 2026, 09:16 AM
- analyzed
- Aug 5, 2026, 09:21 AM
Related advisories
- tailwind-hide-scrollbar@2.1.5
- streak-calc-math@1.0.0
- streak-math-calc@1.0.0
- @rentwise/common@1.0.36
- tailwindcss-scrollbar-hide@2.2.6
- ethers-lib@1.0.3
- bip32-js@1.0.2
- hwi-lib@1.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.