test89078-auth@99.99.99
Malicious code in test89078-auth (npm)
T1082 · System Information DiscoveryT1071.004 · DNST1041 · Exfiltration Over C2 Channel
Analysis
The preinstall hook (node index.js) collects the machine hostname and the current username via os.hostname() and os.userInfo().username, concatenates them, and exfiltrates them through a DNS lookup to a subdomain of the attacker-controlled domain dnshook[.]site (31ee29fe-db68-4fd3-86a2-2b707b9e95f0[.]dnshook[.]site). The DNS query encodes the host identity data in the subdomain label, silently beaconing the victim's machine identity to the remote server on every install.
- analyzed by
- Leitwacht
- first seen
- Sep 17, 2026, 03:06 PM
- analyzed
- Sep 17, 2026, 03:07 PM
Related advisories
- @consts/links@9.9.9
- quartz-core@99.1.9
- message-compiler@9.2.0
- @finaxis/common-js@0.3.3
- sme-rko-finance-front-operations-notifications-impl@35.8.1
- dolyame-ui-cardlogo@35.8.1
- dolyame-ui-contextmenu@35.8.1
- dolyame-ui-contenteditable@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.