LWA-2026-11642 confirmed malware
octopus-action@1.0.1
Malicious code in octopus-action (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1041 · Exfiltration Over C2 Channel
Analysis
The package's preinstall hook runs index.js, which collects system information from the install host — hostname, username, home directory, DNS server addresses, the contents of /etc/passwd and /etc/hosts, and the full package.json — and POSTs it as JSON to the remote endpoint dfwvktnc563cparn1p88c8051w7ovej3[.]oastify[.]com:443 (a Burp Collaborator host). The data is exfiltrated at install time to the attacker-controlled server.
- analyzed by
- Leitwacht
- first seen
- Aug 26, 2026, 01:33 PM
- analyzed
- Aug 26, 2026, 01:33 PM
Related advisories
- spotify-url-infos@3.4.2
- remove-bg-serverless-azure@1.0.1
- openai-pr-reviewer@1.0.0
- hydration-ui-dim@1.0.0
- spf-analytics@1.0.0
- pump-fun-skills@20.1.1
- carbon-monorepo@20.1.1
- optimizely-starter-kit-for-fastly-compute@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.