LWA-2026-5051 confirmed malware

rtms-manager@1.2.0

Malicious code in rtms-manager (npm)

Analysis

Package rtms-manager@1.2.0 runs a preinstall hook that captures the installer's entire environment variables (including NPM_TOKEN, GITHUB_TOKEN, CI/CD secrets) via `env | base64` and exfiltrates them to 244ci90mnvztem0dg1g6nuhreik983ws[.]oastify[.]com via HTTP POST. The attacker uses captured credentials for follow-on supply-chain attacks against other packages the victim has publish access to.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 07:56 AM
analyzed
Jun 13, 2026, 07:59 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.