merge-grid-stats@1.0.0
Malicious code in merge-grid-stats (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols
Analysis
The package's postinstall hook runs install-cb.js, which collects the host's hostname, current working directory, username, and Node.js version and sends them via HTTPS GET to the external endpoint owoemjgpf2c4qxqet92hexzvym4dsq6skvoa2cr[.]oastify[.]com/n2. This outbound beacon fires automatically on every install, exfiltrating environment fingerprint data to an attacker-controlled OAST host.
- analyzed by
- Leitwacht
- first seen
- Aug 6, 2026, 07:39 PM
- analyzed
- Aug 6, 2026, 07:40 PM
Related advisories
- gpt-terminal-cli@1.0.0
- dojo-rn-interview@1.0.1
- wormgpt-cli@1.0.1
- mx-www-locales-common@99.0.0
- poc-ch4rlygr@1.3.0
- move-bcs-codec@1.0.0
- streak-map-cache@1.0.0
- @united-airlines-org/atmos-design-system@40.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.