LWA-2026-5352 MAL-2026-5987 ↗ confirmed malware

ogd-analytics@1.0.0

Malicious code in ogd-analytics (npm)

T1059.004 · Unix ShellT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

ogd-analytics@1.0.0 is an empty skeleton package with a preinstall hook that collects host fingerprint data (hostname, current user, working directory) and POSTs it to webhook[.]site/1ea0386f-dcc0-4f1b-bdbb-61732d6535fb/ogd-analytics — an attacker-controlled data exfiltration endpoint. The package contains no actual analytics functionality.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 09:50 AM
analyzed
Jun 15, 2026, 09:51 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.