LWA-2026-10957 confirmed malware
dependencyfsdsfdsfg@99.9.0
Malicious code in dependencyfsdsfdsfg (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The package's postinstall hook runs index.js, which collects the installer's username (via whoami), hostname, current working directory, and local IPv4 addresses and sends them to the remote endpoint hxxps://xghhv5sajm33m7krgi4n8my0mrsig84x[.]oastify[.]com via an HTTPS GET on install. This is a covert host-metadata beacon that reports the victim machine's identity and network details to an attacker-controlled oastify sinkhole host.
- analyzed by
- Leitwacht
- first seen
- Aug 11, 2026, 08:27 AM
- analyzed
- Aug 11, 2026, 08:27 AM
Related advisories
- ethereum-vault-connector@1.0.0
- @aerodrome-finance/slipstream@1.0.0
- camelot-ammv2-periphery@1.0.0
- boring-vault@1.0.0
- @aerodrome-finance/contracts@1.0.0
- camelot-ammv2-core@1.0.0
- kit-vim-map@1.0.0
- safe-local-env-loader@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.