LWA-2026-3877 MAL-2026-919 ↗ confirmed malware

mds-webcomponents@1.0.2

Malicious code in mds-webcomponents (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

mds-webcomponents@1.0.2 ships a preinstall script (node index.js) that collects host telemetry — hostname, homedir, username, DNS servers, current directory, and the full package.json — then POSTs the data via HTTPS to an OAST callback domain (2mpf1804g4gnfnvuqqx3om0cw32vqlea[.]oastify[.]com). The package has no declared purpose (description: "test", no repository, no README), and the exfiltration to a known intercept/exfil callback host is consistent with a host-info beacon. No token-theft markers found, but the undisclosed preinstall data exfil warrants human review.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 09:21 AM
analyzed
Jun 10, 2026, 09:22 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.