LWA-2026-5026 confirmed malware
riot-private@100.0.0
Malicious code in riot-private (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
The package riot-private@100.0.0 is a dependency-confusion stub (version 100.0.0, ~600 bytes) whose preinstall hook runs index.js. That file collects the installer's hostname, OS platform, and CPU architecture via os.hostname(), os.platform(), os.arch() and sends them as a JSON POST over HTTPS to hwoapraaaotwtsnourpqddszm5n3kkhvo[.]oast[.]fun/paypalcorp. oast[.]fun is an attacker-controlled callback/interactsh-style domain used for data exfiltration and C2.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 07:03 AM
- analyzed
- Jun 13, 2026, 07:05 AM
Related advisories
- rimo-env-validator@1.0.1
- houzidawang808@1.0.0
- houzidawang807@1.1.6
- reseller-app@9.9.11
- sheratan_haha@1.0.0
- renovate-config-doctolib@9.9.16
- redux-init-rce@1.0.0
- redux-probe-unknown-action-rce@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.