node-stack-frames@4.0.0
Malicious code in node-stack-frames (npm)
Analysis
The node-stack-frames@4.0.0 package is an empty package (single version, "Security holding package" description) from a throwaway publisher ([account]) whose sole purpose is its preinstall hook. On `npm install`, the hook runs node -e to collect hostname, platform, and arch metadata, base64-encode it, and GET it to an attacker-controlled OAST callback endpoint (d8lslmi9io6i264ftj80mh9e7niqiaenf[.]oast[.]live). This is a classic host-reconnaissance beacon — postinstall host fingerprinting to an external sink designed to identify targets for follow-on attacks. No token-theft markers found, but the entire package is a single-purpose recon exfiltation payload.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 09:02 AM
- analyzed
- Jun 12, 2026, 09:03 AM
Related advisories
- pino-sdk-v2@9.9.0
- pino-pretty-logs@1.1.0
- pino-pretty-logger@1.1.1
- pino-formatter@1.1.12
- pie-docs@4.31.0
- web-model-bridge@9999.99.99
- period-newline@0.1.0
- peptideenv@16.6.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.