LWA-2026-12573 MAL-2026-17572 ↗ confirmed malware

checkmate-remediation-assistant@1.0.0

Malicious code in checkmate-remediation-assistant (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1087.001 · Local AccountT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

checkmate-remediation-assistant@1.0.0 ships a preinstall hook (`node index.js`) that executes automatically on `npm install`. The hook is the package's entire payload: index.js collects host reconnaissance — package name and install directory, home directory, hostname, username, configured DNS resolvers, package version, the full package.json, and the contents of /etc/passwd and /etc/hosts — and POSTs it as a JSON body over HTTPS to the hardcoded remote endpoint 9q0lp9mr6ek7nrnklhzkmbpuglmda4yt[.]oastify[.]com on port 443 at path "/". The package has no repository, no description, and no functionality other than this collection and exfiltration; the collected system data is sent to an out-of-band callback listener controlled by the package author.

analyzed by
Leitwacht
first seen
Oct 5, 2026, 09:02 AM
analyzed
Oct 5, 2026, 09:12 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.