LWA-2026-4626 confirmed malware
poloman@9.2.1
Malicious code in poloman (npm)
T1059.007 · JavaScriptT1059.004 · Unix ShellT1082 · System Information DiscoveryT1071.004 · DNST1041 · Exfiltration Over C2 Channel
Analysis
A pure reconnaissance beacon (629 bytes, no legitimate functionality). The preinstall hook runs index.js, which executes a shell command collecting hostname, working directory, username (whoami), and the full network interface configuration (ip a), hex-encodes the output with xxd, and exfiltrates it as a series of subdomain DNS queries to the OAST callback host n1pbc7bx5z3ed0c9ty8q6z4p3g97x0lp[.]oastify[.]com. An HTTP GET beacon is also sent to the same host via curl.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 10:14 AM
- analyzed
- Jun 12, 2026, 10:15 AM
Related advisories
- paypal-examples-openai@99.99.9
- paasprint-sdk@9.9.9
- oc-navbar-module-client@9.9.10
- @whatnot-web/www-legacy@99.1.2
- mermaid-v11@9999.0.0
- mimecast-web-components@2.0.0
- sme-rko-finance-front-operations-notifications-impl@35.8.1
- dolyame-ui-cardlogo@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.