mw-filesystem-events-nodream@0.0.32
Malicious code in mw-filesystem-events-nodream (npm)
Analysis
mw-filesystem-events-nodream masquerades as a filesystem-events library but runs index.js via preinstall/install/postinstall hooks to exfiltrate system data through three channels to oastify[.]com: (1) a curl POST of /etc/passwd keyed by hostname, (2) an nslookup DNS exfil of base64-encoded package|hostname|user|platform, and (3) an HTTPS POST of a full system fingerprint (hostname, platform, release, arch, cwd, pid, node version, HOME, PWD, PATH) plus /etc/passwd contents. DNS hits and HTTP captures on 1ikh1ub9ug8oc3qubaud2d6zrqxhl79w[.]oastify[.]com carried the full payload including passwd file contents. The /etc/passwd theft goes well beyond a hostname-only beacon.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 10:12 PM
- analyzed
- Jun 10, 2026, 10:13 PM
Related advisories
- solana-core-4@1.0.0
- ethereum-kit-1@1.0.0
- solana-web3-stable@1.0.0
- solana-rpc-client@1.0.0
- solana-web3-patched@1.0.0
- solana-web3-fixed@1.0.0
- solana-js-client@1.0.0
- solana-web3-fork@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.