LWA-2026-11642 confirmed malware

octopus-action@1.0.1

Malicious code in octopus-action (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1041 · Exfiltration Over C2 Channel

Analysis

The package's preinstall hook runs index.js, which collects system information from the install host — hostname, username, home directory, DNS server addresses, the contents of /etc/passwd and /etc/hosts, and the full package.json — and POSTs it as JSON to the remote endpoint dfwvktnc563cparn1p88c8051w7ovej3[.]oastify[.]com:443 (a Burp Collaborator host). The data is exfiltrated at install time to the attacker-controlled server.

analyzed by
Leitwacht
first seen
Aug 26, 2026, 01:33 PM
analyzed
Aug 26, 2026, 01:33 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.