test890-auth@1.0.0
Malicious code in test890-auth (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The package's preinstall hook runs index.js, which collects host metadata (hostname, username, home directory, DNS server list, working directory, and the package.json contents) and POSTs it over HTTPS to wddbracmbzlaffkl9eivxzsvamgd43ss[.]oastify[.]com:443. This is a host-recon beacon to an OAST-style exfiltration endpoint.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 02:14 PM
- analyzed
- Sep 18, 2026, 02:15 PM
Related advisories
- my-ctf-helper-script-9921@1.0.0
- sorrawit-dev-helper@1.0.0
- chai-as-indexed@7.2.8
- montreal-core@0.1.0
- catwrestlingbird@1.0.0
- @tink/tink-link-core@9.9.10
- homestack-cheer@1.1.9
- test89078-auth@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.