tn-advertisement@5.0.0
Malicious code in tn-advertisement (npm)
T1059.007 · JavaScriptT1071.001 · Web Protocols
Analysis
When the package is loaded via require(), its index.js executes an HTTP GET request to ovn8duk7sx82csy4uskidmibt2ztnkb9[.]oastify[.]com (an external callback/listener service). The package has no other functionality — its entire code is this outbound beacon. The request is a plain GET to the root path of that host, serving as a callback that signals the package was installed and executed on the victim's system. The C2 host is ovn8duk7sx82csy4uskidmibt2ztnkb9[.]oastify[.]com on port 80.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 06:48 PM
- analyzed
- Jun 14, 2026, 06:49 PM
Related advisories
- tecken@0.1.10
- tailwind-scroller@1.0.2
- tailwindcss-svg-helper@1.17.9
- tailwindcss-framer-motion@1.1.3
- tailwindcss-devtools@1.4.0
- electron-internal-utils@1.0.0
- tailwindcss-animate-builder@2.1.0
- tailmagic@2.3.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.