@monitoring-lib/error-tracking@9999.0.0
Malicious code in @monitoring-lib/error-tracking (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1195.002 · Compromise Software Supply Chain
Analysis
@monitoring-lib/error-tracking is a dependency-confusion stub (version 9999.0.0, ~530 bytes, no library code) whose preinstall hook collects os.hostname() and os.userInfo().username and exfiltrates them via an HTTPS GET to d8ks495t5p5ut2enft8041g7fusnfsy5e[.]oast[.]site/?h=HOST&u=USER&pkg=..., and simultaneously via a DNS lookup to monitoring-lib[.]HOST.d8ks495t5p5ut2enft8041g7fusnfsy5e[.]oast[.]site — out-of-band host-metadata exfiltration as part of a dependency-confusion supply-chain attack.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 12:35 AM
- analyzed
- Jun 11, 2026, 12:36 AM
Related advisories
- mermaid-v11@9999.0.0
- mypocmaliciouspackage-cursorpt1@4.0.0
- @coze-common/chat-area@99.1.1
- mw-filesystem-events-nodream_compat@99.99.99
- mw-filesystem-events-nodream-es6@0.0.32
- mw-filesystem-events-nodream@0.0.32
- mpesa-ui-components@1.1.20
- motion-lib@2.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.