LWA-2026-4063 MAL-2026-5544 ↗ confirmed malware

pocteszep@1.0.0

Malicious code in pocteszep (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1071.001 · Web Protocols

Analysis

pocteszep@1.0.0 is an empty namespace-claim package (only package.json, no code files) with a preinstall hook that curls an oastify[.]com OAST beacon URL, suppressing output and errors. The publisher begbounty18/[account] is a throwaway account. No token-theft markers present (no NPM_TOKEN, .npmrc, env reads). The package has no README, no repository URL, no description — no verifiable research provenance. However, this is a live supply-chain recon beacon: the preinstall fires an out-of-band callback to oastify[.]com on every install, confirming to the publisher that the package is being installed in environments that allow egress. While it does not currently exfil secrets or download second-stage payloads, it is a clear precursor to a real supply-chain attack — establishing a callback channel before deploying a malicious payload in a later version.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 01:27 AM
analyzed
Jun 11, 2026, 01:28 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.