LWA-2026-4023 MAL-2026-3409 ↗ confirmed malware

mw-filesystem-events-nodream@0.0.32

Malicious code in mw-filesystem-events-nodream (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

mw-filesystem-events-nodream masquerades as a filesystem-events library but runs index.js via preinstall/install/postinstall hooks to exfiltrate system data through three channels to oastify[.]com: (1) a curl POST of /etc/passwd keyed by hostname, (2) an nslookup DNS exfil of base64-encoded package|hostname|user|platform, and (3) an HTTPS POST of a full system fingerprint (hostname, platform, release, arch, cwd, pid, node version, HOME, PWD, PATH) plus /etc/passwd contents. DNS hits and HTTP captures on 1ikh1ub9ug8oc3qubaud2d6zrqxhl79w[.]oastify[.]com carried the full payload including passwd file contents. The /etc/passwd theft goes well beyond a hostname-only beacon.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 10:12 PM
analyzed
Jun 10, 2026, 10:13 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.