LWA-2026-10961 confirmed malware

ghazaly@99.9.0

Malicious code in ghazaly (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The postinstall hook runs index.js, which fingerprints the host (hostname, current username via whoami, working directory, and local IPv4 addresses) and exfiltrates them to the attacker-controlled endpoint hxxps://xghhv5sajm33m7krgi4n8my0mrsig84x[.]oastify[.]com via an HTTPS GET. The package also depends on the known-malicious package dependencyfsdsfdsfg.

analyzed by
Leitwacht
first seen
Aug 11, 2026, 09:04 AM
analyzed
Aug 11, 2026, 09:04 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.