LWA-2026-11495 confirmed malware

carbon-monorepo@20.1.1

Malicious code in carbon-monorepo (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The postinstall hook runs index.js, which executes system commands (whoami, uname -a, cat /etc/passwd, cat /etc/shadow, ps aux) and collects the full process environment, hostname, platform, current working directory, package.json contents, and the node_modules listing, then POSTs all of it to the remote host ywy8qnd4a931ga4v74k70b9g67c00qof[.]oastify[.]com on port 80. The package is named and described as an esbuild platform build but is unrelated to esbuild.

analyzed by
Leitwacht
first seen
Aug 19, 2026, 12:16 AM
analyzed
Aug 19, 2026, 12:16 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.