LWA-2026-10957 confirmed malware

dependencyfsdsfdsfg@99.9.0

Malicious code in dependencyfsdsfdsfg (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package's postinstall hook runs index.js, which collects the installer's username (via whoami), hostname, current working directory, and local IPv4 addresses and sends them to the remote endpoint hxxps://xghhv5sajm33m7krgi4n8my0mrsig84x[.]oastify[.]com via an HTTPS GET on install. This is a covert host-metadata beacon that reports the victim machine's identity and network details to an attacker-controlled oastify sinkhole host.

analyzed by
Leitwacht
first seen
Aug 11, 2026, 08:27 AM
analyzed
Aug 11, 2026, 08:27 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.