test899-auth@1.0.1
Malicious code in test899-auth (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1048.003 · Exfiltration Over Alternative ProtocolT1071.004 · DNS
Analysis
The preinstall hook executes index.js, which collects host device information (hostname, platform, architecture, OS release, uptime, CPU count, total memory, and the output of whoami, id, pwd, and uname -a) and exfiltrates it over DNS. The data is base64url-encoded, split into 50-character chunks, and transmitted as nslookup queries to the DNS callback domain hufw8vt7sk2vw016qzzgek9gr7x0ls9h[.]oastify[.]com, using a session-id prefix and a chunk-count beacon for reassembly. The package also declares a dependency on itself (test899-auth ^1.0.1).
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 02:50 PM
- analyzed
- Sep 18, 2026, 02:52 PM
Related advisories
- @consts/links@9.9.9
- devplatform-auth-client@35.2.1
- oc-navbar-module-client@9.9.10
- @insiderintelligence/componentlibrary@9.9.10
- test89-auth@1.0.1
- @tink/tink-link-core@9.9.10
- test89078-auth@99.99.99
- quartz-core@99.1.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.