LWA-2026-10635 MAL-2026-13454 ↗ confirmed malware

poc-ch4rlygr@1.3.0

Malicious code in poc-ch4rlygr (npm)

T1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The package's main entry point (index.js) is an environment/credential exfiltration beacon. On require it collects the hostname, OS architecture, install directory, current username, and the full process environment (every environment variable serialized as key=value pairs, including any tokens or credentials present), then sends them via an HTTPS GET to the Burp Collaborator host zuxsp9k9vyk5y45z1n2hv0orhin9b2zr[.]oastify[.]com at path /poc with the collected data in the query string.

analyzed by
Leitwacht
first seen
Aug 6, 2026, 05:11 PM
analyzed
Aug 6, 2026, 05:11 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.