LWA-2026-3146 MAL-2026-5415 ↗ confirmed malware

@klapp-login-platform/routes@99.0.2

Malicious code in @klapp-login-platform/routes (npm)

T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages

Analysis

@klapp-login-platform/routes@99.0.2 is an 808-byte dependency-confusion stub whose preinstall hook (node index.js || true) fires index.js, a dual-channel host-metadata beacon. It collects hostname, username, __dirname and cwd, hex-encodes them, and exfiltrates via a DNS resolution to the callback domain d8jbmnsqcfu78dfs8vdg34ohqhirb4pbg.oast[.]live and an HTTP POST of the same JSON to 172[.]201[.]213[.]59:9090/c. The 'security research' description has no repository URL or program reference and masks the dual-exfil stealer.

analyzed by
Leitwacht
first seen
Jun 8, 2026, 01:41 PM
analyzed
Jun 8, 2026, 01:44 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.