LWA-2026-4024 confirmed malware

mw-filesystem-events-nodream_compat@99.99.99

Malicious code in mw-filesystem-events-nodream_compat (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1048 · Exfiltration Over Alternative Protocol

Analysis

A combosquat/dependency-confusion package whose preinstall hook reads /etc/passwd, /etc/shadow, ~/.ssh/id_rsa, ~/.aws/credentials, ~/.npmrc, .env, and environment variables, then exfiltrates them to 98fc2q4edg6ycjvebn0x9nmbg2mtamyb[.]oastify[.]com via HTTPS POST to /exfil and also via DNS subdomain queries. The postinstall hook beacons detailed host/network/process information to the same host. The package is a credential-theft and host-enumeration implant targeting developer machines that run npm install.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 10:12 PM
analyzed
Jun 10, 2026, 10:14 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.