LWA-2026-11496 confirmed malware

pump-fun-skills@20.1.1

Malicious code in pump-fun-skills (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The postinstall hook runs index.js, which collects the hostname, full process environment variables, platform/arch, the current package.json, the node_modules directory listing, and the output of `whoami`, `uname -a`, `cat /etc/passwd`, `cat /etc/shadow`, and `ps aux`, then POSTs all of it over plain HTTP to the C2 host 6lsgfv2czhs95it3wc9fpjyovf19pzdo[.]oastify[.]com:80. The package is named pump-fun-skills but describes itself as an esbuild build, an unrelated identity.

analyzed by
Leitwacht
first seen
Aug 19, 2026, 12:31 AM
analyzed
Aug 19, 2026, 12:31 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.