LWA-2026-10106 MAL-2026-12383 ↗ confirmed malware

foodi@99.99.1

Malicious code in foodi (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel

Analysis

foodi@99.99.1 runs a curl command in both its preinstall and postinstall hooks that POSTs the installer's username, hostname, and full environment variables (including any credentials/tokens present) to the remote host hxxps://y0zhmssf65c8er7btoglvt9bg2mtakc81[.]oastify[.]com, using -k to skip TLS verification and suppressing errors with `|| true`. The package is a 447-byte stub published at version 99.99.1 with no functional code, matching a dependency-confusion squat shape. The environment dump exfiltrates secrets such as npm/GitHub/cloud tokens to the attacker-controlled callback host.

analyzed by
Leitwacht
first seen
Aug 5, 2026, 10:28 AM
analyzed
Aug 5, 2026, 10:33 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.