LWA-2026-11495 confirmed malware
carbon-monorepo@20.1.1
Malicious code in carbon-monorepo (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The postinstall hook runs index.js, which executes system commands (whoami, uname -a, cat /etc/passwd, cat /etc/shadow, ps aux) and collects the full process environment, hostname, platform, current working directory, package.json contents, and the node_modules listing, then POSTs all of it to the remote host ywy8qnd4a931ga4v74k70b9g67c00qof[.]oastify[.]com on port 80. The package is named and described as an esbuild platform build but is unrelated to esbuild.
- analyzed by
- Leitwacht
- first seen
- Aug 19, 2026, 12:16 AM
- analyzed
- Aug 19, 2026, 12:16 AM
Related advisories
- optimizely-starter-kit-for-fastly-compute@1.0.1
- prism-registry@1.0.1
- @evial/runtime-health@1.0.0
- @evial/init-helper-djkwt@1.0.0
- sysdo@1.0.0
- require-i18next@20.0.0
- @openrepl/shared@0.0.4
- hunterone-build-probe-9210@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.