LWA-2026-12242 MAL-2026-16285 ↗ confirmed malware

test899-auth@1.0.1

Malicious code in test899-auth (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1048.003 · Exfiltration Over Alternative ProtocolT1071.004 · DNS

Analysis

The preinstall hook executes index.js, which collects host device information (hostname, platform, architecture, OS release, uptime, CPU count, total memory, and the output of whoami, id, pwd, and uname -a) and exfiltrates it over DNS. The data is base64url-encoded, split into 50-character chunks, and transmitted as nslookup queries to the DNS callback domain hufw8vt7sk2vw016qzzgek9gr7x0ls9h[.]oastify[.]com, using a session-id prefix and a chunk-count beacon for reassembly. The package also declares a dependency on itself (test899-auth ^1.0.1).

analyzed by
Leitwacht
first seen
Sep 18, 2026, 02:50 PM
analyzed
Sep 18, 2026, 02:52 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.