LWA-2026-5050 confirmed malware
rtms-manager@1.0.0
Malicious code in rtms-manager (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.004 · DNS
Analysis
rtms-manager@1.0.0 is a dependency-confusion package with a preinstall hook (node index.js) that exfiltrates the installer's username and hostname via DNS to an oastify[.]com (Interactsh) callback domain. On installation, the script runs os.userInfo().username and os.hostname(), constructs a domain cb.{username}.{hostname}.vih5w2ef1odmsfe6uuuz1nvksby2mvak[.]oastify[.]com, and performs a dns.lookup to the oastify[.]com domain — a blind out-of-band exfiltration technique. The package has no legitimate functionality and is published only to execute this beacon.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 07:56 AM
- analyzed
- Jun 13, 2026, 07:57 AM
Related advisories
- rtms-manager@1.2.0 same package
- reseller-app@9.9.11
- rendezvous-js@9.9.11
- qr-code-styling-temp@9.9.10
- atlassian-forge-skills@29.1.0
- poloman@9.2.1
- paypal-examples-openai@99.99.9
- paasprint-sdk@9.9.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.