dt-fe-t2d-marketplace@71.0.2
Malicious code in dt-fe-t2d-marketplace (npm)
Analysis
dt-fe-t2d-marketplace@71.0.2 is a dependency-confusion package whose preinstall hook runs index.js to collect system info (whoami/hostname/pwd/id/ls) and exfiltrate it via HTTPS POST to an out-of-band callback host (10za7dbmrvoib5iizpa8sa01gsmjaa2yr[.]oastify[.]com) with User-Agent 'rce-minimal-demo'. The description "This is a test for dependency confusion" has no repository or program reference.
- analyzed by
- Leitwacht
- first seen
- Jun 1, 2026, 05:26 PM
- analyzed
- Jun 1, 2026, 05:34 PM
Related advisories
- @catamania/front-components@1.0.2
- @convera/ui-shared@0.0.2
- @convera/ui-shared@0.0.3
- msc-terminal@3.2.0
- @asavie/i18n@99.0.3
- forge-jsxy@1.0.91
- eslint-plugin-vitest-ts@1.0.4
- fundraiserserv@28.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.