LWA-2026-5050 confirmed malware

rtms-manager@1.0.0

Malicious code in rtms-manager (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.004 · DNS

Analysis

rtms-manager@1.0.0 is a dependency-confusion package with a preinstall hook (node index.js) that exfiltrates the installer's username and hostname via DNS to an oastify[.]com (Interactsh) callback domain. On installation, the script runs os.userInfo().username and os.hostname(), constructs a domain cb.{username}.{hostname}.vih5w2ef1odmsfe6uuuz1nvksby2mvak[.]oastify[.]com, and performs a dns.lookup to the oastify[.]com domain — a blind out-of-band exfiltration technique. The package has no legitimate functionality and is published only to execute this beacon.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 07:56 AM
analyzed
Jun 13, 2026, 07:57 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.