checkmate-remediation-assistant@1.0.0
Malicious code in checkmate-remediation-assistant (npm)
Analysis
checkmate-remediation-assistant@1.0.0 ships a preinstall hook (`node index.js`) that executes automatically on `npm install`. The hook is the package's entire payload: index.js collects host reconnaissance — package name and install directory, home directory, hostname, username, configured DNS resolvers, package version, the full package.json, and the contents of /etc/passwd and /etc/hosts — and POSTs it as a JSON body over HTTPS to the hardcoded remote endpoint 9q0lp9mr6ek7nrnklhzkmbpuglmda4yt[.]oastify[.]com on port 443 at path "/". The package has no repository, no description, and no functionality other than this collection and exfiltration; the collected system data is sent to an out-of-band callback listener controlled by the package author.
- analyzed by
- Leitwacht
- first seen
- Oct 5, 2026, 09:02 AM
- analyzed
- Oct 5, 2026, 09:12 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.