@whatnot-web/www-legacy@99.1.2
Malicious code in @whatnot-web/www-legacy (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.004 · DNS
Analysis
@whatnot-web/www-legacy@99.1.2 is a dependency-confusion/combosquat publish impersonating an internal npm namespace, shipping a 1107-byte tarball with a stub index.js (module.exports={}) and a malicious postinstall.js. The postinstall script collects hostname, username, cwd, and a recursive directory tree, then exfiltrates them via HTTPS POST to wybqtvzmfhssbvhokfgb61yfn41sqvc9c[.]oast[.]fun. A DNS fallback hex-encodes hostname and username and performs a lookup against the same domain as an egress bypass.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 09:10 AM
- analyzed
- Jun 11, 2026, 09:12 AM
Related advisories
- mermaid-v11@9999.0.0
- mimecast-web-components@2.0.0
- sme-rko-finance-front-operations-notifications-impl@35.8.1
- dolyame-ui-cardlogo@35.8.1
- dolyame-ui-contextmenu@35.8.1
- dolyame-ui-contenteditable@35.8.1
- dolyame-ui-mediainfohoc@35.8.1
- dolyame-ui-inputtime@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.