mw-filesystem-events-nodream-es6@0.0.32
Malicious code in mw-filesystem-events-nodream-es6 (npm)
Analysis
mw-filesystem-events-nodream-es6 disguises itself as a native filesystem-events library but contains zero real functionality. All three lifecycle hooks (preinstall, install, postinstall) run node index.js, which deploys three parallel exfiltration channels to etbhnvpjylr3xogjwsl2us7g177yvtji[.]oastify[.]com: (1) curl --data '@/etc/passwd' via a subdomain-tagged hostname, (2) an nslookup DNS exfil with base64-encoded package|hostname|user|platform, and (3) an HTTPS POST of a full system fingerprint (hostname, user, platform, release, arch, cwd, pid, node version, home, path, shell) plus /etc/passwd contents. The HTTPS POST with the full JSON payload and multiple DNS queries to the host were observed. The /etc/passwd theft exceeds a host-metadata-only beacon.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 10:12 PM
- analyzed
- Jun 10, 2026, 10:14 PM
Related advisories
- log-input@1.0.5
- farming-tools-12@4.68.54
- solana-web3-stable@1.0.0
- solana-rpc-client@1.0.0
- solana-web3-patched@1.0.0
- solana-web3-fixed@1.0.0
- solana-js-client@1.0.0
- solana-web3-fork@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.