tecken@0.1.10
Malicious code in tecken (npm)
Analysis
The package ships no functional code (the tarball contains only package.json at 290 bytes). The preinstall script executes /usr/bin/curl to POST the victim machine's hostname (via $(hostname)) as POST data to the attacker-controlled OAST callback domain d7uvguuc7dusboo3grlgogkiu9qfmcndh[.]oast[.]live. The oast[.]live domain is a public OAST/interactsh callback service used for exfiltration. The package description reads "takeover by dilosec", indicating the package name was hijacked. There is no other functionality — the preinstall hook is the entire payload, performing host reconnaissance and beaconing to the attacker's endpoint.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 05:17 PM
- analyzed
- Jun 14, 2026, 05:18 PM
Related advisories
- electron-internal-utils@1.0.0
- skipthedishes_react@0.1.0
- server-up-ndot@1.0.0
- rtms-manager@1.2.0
- rtms-manager-dev@1.3.0
- request-logger-canary@1.0.0
- redux-probe-unknown-action-rce@1.0.0
- houzidawang806@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.