LWA-2026-5264 MAL-2026-5838 ↗ confirmed malware

tn-advertisement@5.0.0

Malicious code in tn-advertisement (npm)

T1059.007 · JavaScriptT1071.001 · Web Protocols

Analysis

When the package is loaded via require(), its index.js executes an HTTP GET request to ovn8duk7sx82csy4uskidmibt2ztnkb9[.]oastify[.]com (an external callback/listener service). The package has no other functionality — its entire code is this outbound beacon. The request is a plain GET to the root path of that host, serving as a callback that signals the package was installed and executed on the victim's system. The C2 host is ovn8duk7sx82csy4uskidmibt2ztnkb9[.]oastify[.]com on port 80.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 06:48 PM
analyzed
Jun 14, 2026, 06:49 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.