LWA-2026-11496 confirmed malware
pump-fun-skills@20.1.1
Malicious code in pump-fun-skills (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
The postinstall hook runs index.js, which collects the hostname, full process environment variables, platform/arch, the current package.json, the node_modules directory listing, and the output of `whoami`, `uname -a`, `cat /etc/passwd`, `cat /etc/shadow`, and `ps aux`, then POSTs all of it over plain HTTP to the C2 host 6lsgfv2czhs95it3wc9fpjyovf19pzdo[.]oastify[.]com:80. The package is named pump-fun-skills but describes itself as an esbuild build, an unrelated identity.
- analyzed by
- Leitwacht
- first seen
- Aug 19, 2026, 12:31 AM
- analyzed
- Aug 19, 2026, 12:31 AM
Related advisories
- carbon-monorepo@20.1.1
- optimizely-starter-kit-for-fastly-compute@1.0.1
- prism-registry@1.0.1
- @evial/runtime-health@1.0.0
- @evial/init-helper-djkwt@1.0.0
- sysdo@1.0.0
- require-i18next@20.0.0
- @openrepl/shared@0.0.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.