LWA-2026-11031 confirmed malware

verify-cli@99.0.0

Malicious code in verify-cli (npm)

Analysis

The package's preinstall hook runs node index.js, which executes a curl POST to the attacker-controlled host 5f8a1ed70fb7761d678agw9bucryyyyyb[.]oast[.]site. The URL path embeds the victim's username and hostname, and the User-Agent header carries base64-encoded contents of /etc/passwd, /etc/hosts, the output of `id`, and /etc/shadow (when readable). This exfiltrates system identity and credential data to the remote host on install. The package also declares a dependency on noderedacteddk@¹.0.2, an invalid version tag that breaks installation.

analyzed by
Leitwacht
first seen
Aug 12, 2026, 08:55 AM
analyzed
Aug 12, 2026, 09:40 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.