foodi@99.99.1
Malicious code in foodi (npm)
Analysis
foodi@99.99.1 runs a curl command in both its preinstall and postinstall hooks that POSTs the installer's username, hostname, and full environment variables (including any credentials/tokens present) to the remote host hxxps://y0zhmssf65c8er7btoglvt9bg2mtakc81[.]oastify[.]com, using -k to skip TLS verification and suppressing errors with `|| true`. The package is a 447-byte stub published at version 99.99.1 with no functional code, matching a dependency-confusion squat shape. The environment dump exfiltrates secrets such as npm/GitHub/cloud tokens to the attacker-controlled callback host.
- analyzed by
- Leitwacht
- first seen
- Aug 5, 2026, 10:28 AM
- analyzed
- Aug 5, 2026, 10:33 AM
Related advisories
- streak-calc-math@1.0.0
- streak-math-calc@1.0.0
- ethers-lib@1.0.3
- bip32-js@1.0.2
- hwi-lib@1.0.2
- ckcc-protocol@1.0.2
- trezor-lib@1.0.2
- ledger-lib@1.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.