LWA-2026-5052 confirmed malware
rtms-manager-dev@1.3.0
Malicious code in rtms-manager-dev (npm)
Analysis
Package rtms-manager-dev@1.3.0 runs a preinstall hook that captures the installer's entire environment variables (including NPM_TOKEN, GITHUB_TOKEN, CI/CD secrets) via `env | base64` and exfiltrates them to the remote host 244ci90mnvztem0dg1g6nuhreik983ws[.]oastify[.]com via HTTP POST. The attacker collects environment credentials for use in follow-on supply-chain attacks against other packages the victim has access to.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 07:56 AM
- analyzed
- Jun 13, 2026, 07:59 AM
Related advisories
- houzidawang806@1.0.1
- @ci-lifecycle-test/postinstall-ping@1.0.0
- pumpdotfun-sdk-v3.0@3.1.3
- program-commander@14.1.9
- polymarket-trading-cli@0.1.0
- polymarket-trader@0.1.0
- polymarket-terminal@0.1.0
- polymarket-onchain-plugin@2.1.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.