poc-ch4rlygr@1.3.0
Malicious code in poc-ch4rlygr (npm)
T1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
The package's main entry point (index.js) is an environment/credential exfiltration beacon. On require it collects the hostname, OS architecture, install directory, current username, and the full process environment (every environment variable serialized as key=value pairs, including any tokens or credentials present), then sends them via an HTTPS GET to the Burp Collaborator host zuxsp9k9vyk5y45z1n2hv0orhin9b2zr[.]oastify[.]com at path /poc with the collected data in the query string.
- analyzed by
- Leitwacht
- first seen
- Aug 6, 2026, 05:11 PM
- analyzed
- Aug 6, 2026, 05:11 PM
Related advisories
- move-bcs-codec@1.0.0
- streak-map-cache@1.0.0
- tailwindcss-hide-scrollbar@2.5.4
- nhdxzthponv5@1.0.0
- streak-cache-map@1.0.0
- app-api-sdk@2.1.7
- app-kst-engine@2.1.6
- dlab_workshop@1.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.