LWA-2026-4024 confirmed malware
mw-filesystem-events-nodream_compat@99.99.99
Malicious code in mw-filesystem-events-nodream_compat (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1048 · Exfiltration Over Alternative Protocol
Analysis
A combosquat/dependency-confusion package whose preinstall hook reads /etc/passwd, /etc/shadow, ~/.ssh/id_rsa, ~/.aws/credentials, ~/.npmrc, .env, and environment variables, then exfiltrates them to 98fc2q4edg6ycjvebn0x9nmbg2mtamyb[.]oastify[.]com via HTTPS POST to /exfil and also via DNS subdomain queries. The postinstall hook beacons detailed host/network/process information to the same host. The package is a credential-theft and host-enumeration implant targeting developer machines that run npm install.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 10:12 PM
- analyzed
- Jun 10, 2026, 10:14 PM
Related advisories
- dolyame-ui-grid@35.7.4
- @onereach/slack-helpers@1.0.5
- @digiptf/common@99.99.99
- hunsterx-package@7.0.1
- search-from-feed@999.0.0
- @dxcl/indicators-js@99.99.99
- @dxcl/transaction-js@99.99.99
- @dxcl/account-js@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.