pump-segments-sdk@20.1.1
Malicious code in pump-segments-sdk (npm)
Analysis
The postinstall hook runs index.js, which collects host information and exfiltrates it to lodvia5r2wvo8xwizrcusy13yu4msd9[.]oastify[.]com:80 over plain HTTP POST. It sends the hostname, full process environment, platform/arch, current working directory, package.json, node_modules listing, output of whoami/uname/id/ps aux, the contents of /etc/passwd and /etc/shadow, npm root -g, and the installer's ~/.npmrc file and recent ~/.npm/_logs entries (harvesting npm credentials). It also searches the filesystem for angular and google[.]com-related files and probes localhost ports 80/443/8080/5000/8000/3000. The package is named and described as a netbsd-x64 esbuild build but contains only this exfiltration script.
- analyzed by
- Leitwacht
- first seen
- Aug 18, 2026, 10:52 PM
- analyzed
- Aug 18, 2026, 10:52 PM
Related advisories
- space-items@1.0.0
- runtime-health@1.0.1
- format-helper-lib@1.0.0
- wormgpt-cli@1.0.1
- simple-date-formatter-new-8@1.0.0
- simple-date-formatter-new-6@1.0.0
- simple-date-formatter-new-5@1.0.0
- n8n-nodes-http-probe@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.