LWA-2026-4613 MAL-2026-5736 ↗ confirmed malware

node-stack-frames@4.0.0

Malicious code in node-stack-frames (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The node-stack-frames@4.0.0 package is an empty package (single version, "Security holding package" description) from a throwaway publisher ([account]) whose sole purpose is its preinstall hook. On `npm install`, the hook runs node -e to collect hostname, platform, and arch metadata, base64-encode it, and GET it to an attacker-controlled OAST callback endpoint (d8lslmi9io6i264ftj80mh9e7niqiaenf[.]oast[.]live). This is a classic host-reconnaissance beacon — postinstall host fingerprinting to an external sink designed to identify targets for follow-on attacks. No token-theft markers found, but the entire package is a single-purpose recon exfiltation payload.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 09:02 AM
analyzed
Jun 12, 2026, 09:03 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.