mds-webcomponents@1.0.2
Malicious code in mds-webcomponents (npm)
Analysis
mds-webcomponents@1.0.2 ships a preinstall script (node index.js) that collects host telemetry — hostname, homedir, username, DNS servers, current directory, and the full package.json — then POSTs the data via HTTPS to an OAST callback domain (2mpf1804g4gnfnvuqqx3om0cw32vqlea[.]oastify[.]com). The package has no declared purpose (description: "test", no repository, no README), and the exfiltration to a known intercept/exfil callback host is consistent with a host-info beacon. No token-theft markers found, but the undisclosed preinstall data exfil warrants human review.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 09:21 AM
- analyzed
- Jun 10, 2026, 09:22 AM
Related advisories
- farming-tools-12@4.68.54
- os-ulid-void@3.0.2
- wallet-sdk-9@3.7.73
- solana-core-4@1.0.0
- ethereum-kit-1@1.0.0
- events-runtime@3.2.1
- map-streak-kit@1.0.0
- titan-exchange-shared-permissions@99.9.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.