ogd-analytics@1.0.0
Malicious code in ogd-analytics (npm)
T1059.004 · Unix ShellT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
ogd-analytics@1.0.0 is an empty skeleton package with a preinstall hook that collects host fingerprint data (hostname, current user, working directory) and POSTs it to webhook[.]site/1ea0386f-dcc0-4f1b-bdbb-61732d6535fb/ogd-analytics — an attacker-controlled data exfiltration endpoint. The package contains no actual analytics functionality.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 09:50 AM
- analyzed
- Jun 15, 2026, 09:51 AM
Related advisories
- nic-datagov@1.0.0
- ts-enum-helper@1.0.0
- tether-base@99.0.0
- tecken@0.1.10
- electron-internal-utils@1.0.0
- skipthedishes_react@0.1.0
- server-up-ndot@1.0.0
- rtms-manager@1.2.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.