LWA-2026-10961 confirmed malware
ghazaly@99.9.0
Malicious code in ghazaly (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The postinstall hook runs index.js, which fingerprints the host (hostname, current username via whoami, working directory, and local IPv4 addresses) and exfiltrates them to the attacker-controlled endpoint hxxps://xghhv5sajm33m7krgi4n8my0mrsig84x[.]oastify[.]com via an HTTPS GET. The package also depends on the known-malicious package dependencyfsdsfdsfg.
- analyzed by
- Leitwacht
- first seen
- Aug 11, 2026, 09:04 AM
- analyzed
- Aug 11, 2026, 09:04 AM
Related advisories
- permit2@1.0.0
- dependencyfsdsfdsfg@99.9.0
- ethereum-vault-connector@1.0.0
- @aerodrome-finance/slipstream@1.0.0
- camelot-ammv2-periphery@1.0.0
- boring-vault@1.0.0
- @aerodrome-finance/contracts@1.0.0
- camelot-ammv2-core@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.