LWA-2026-4055 MAL-2026-5540 ↗ confirmed malware

@monitoring-lib/error-tracking@9999.0.0

Malicious code in @monitoring-lib/error-tracking (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1195.002 · Compromise Software Supply Chain

Analysis

@monitoring-lib/error-tracking is a dependency-confusion stub (version 9999.0.0, ~530 bytes, no library code) whose preinstall hook collects os.hostname() and os.userInfo().username and exfiltrates them via an HTTPS GET to d8ks495t5p5ut2enft8041g7fusnfsy5e[.]oast[.]site/?h=HOST&u=USER&pkg=..., and simultaneously via a DNS lookup to monitoring-lib[.]HOST.d8ks495t5p5ut2enft8041g7fusnfsy5e[.]oast[.]site — out-of-band host-metadata exfiltration as part of a dependency-confusion supply-chain attack.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 12:35 AM
analyzed
Jun 11, 2026, 12:36 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.