LWA-2026-11494 confirmed malware

pump-segments-sdk@20.1.1

Malicious code in pump-segments-sdk (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1046 · Network Service DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The postinstall hook runs index.js, which collects host information and exfiltrates it to lodvia5r2wvo8xwizrcusy13yu4msd9[.]oastify[.]com:80 over plain HTTP POST. It sends the hostname, full process environment, platform/arch, current working directory, package.json, node_modules listing, output of whoami/uname/id/ps aux, the contents of /etc/passwd and /etc/shadow, npm root -g, and the installer's ~/.npmrc file and recent ~/.npm/_logs entries (harvesting npm credentials). It also searches the filesystem for angular and google[.]com-related files and probes localhost ports 80/443/8080/5000/8000/3000. The package is named and described as a netbsd-x64 esbuild build but contains only this exfiltration script.

analyzed by
Leitwacht
first seen
Aug 18, 2026, 10:52 PM
analyzed
Aug 18, 2026, 10:52 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.