slow-surf@10.0.0
Malicious code in slow-surf (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
slow-surf@10.0.0 runs a preinstall hook (node notify.js) that collects system information — hostname, username, current working directory, NODE_ENV, and CPU architecture — and exfiltrates it via HTTPS POST to webhook[.]site/4d0cc13d-a185-4e95-92dc-f4681125055c. The payload is a host-metadata beacon that fingerprints the installation environment.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 01:03 AM
- analyzed
- Jun 14, 2026, 01:04 AM
Related advisories
- skipthedishes_react@0.1.0
- sjs-lint-build1@1.0.4
- sjs-builders@1.0.4
- sisubeny-bun-pwn-payload-1@1.0.0
- signature-transaction@1.1.0
- sickle-wrapper@0.2.0
- shadcn-ui-autocomplete@3.5.0
- sftc-advance-components@0.9.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.