LWA-2026-4626 confirmed malware

poloman@9.2.1

Malicious code in poloman (npm)

T1059.007 · JavaScriptT1059.004 · Unix ShellT1082 · System Information DiscoveryT1071.004 · DNST1041 · Exfiltration Over C2 Channel

Analysis

A pure reconnaissance beacon (629 bytes, no legitimate functionality). The preinstall hook runs index.js, which executes a shell command collecting hostname, working directory, username (whoami), and the full network interface configuration (ip a), hex-encodes the output with xxd, and exfiltrates it as a series of subdomain DNS queries to the OAST callback host n1pbc7bx5z3ed0c9ty8q6z4p3g97x0lp[.]oastify[.]com. An HTTP GET beacon is also sent to the same host via curl.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 10:14 AM
analyzed
Jun 12, 2026, 10:15 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.