LWA-2026-5354 MAL-2026-5828 ↗ confirmed malware

ogd-platform@1.0.0

Malicious code in ogd-platform (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

ogd-platform@1.0.0 contains no functional code — only a preinstall lifecycle hook in package.json. On npm install, the hook runs hostname, whoami, and pwd to collect host system information, then exfiltrates this data via curl POST to hxxps://webhook[.]site/1ea0386f-dcc0-4f1b-bdbb-61732d6535fb/ogd-platform (a webhook[.]site endpoint commonly used for data collection).

analyzed by
Leitwacht
first seen
Jun 15, 2026, 09:50 AM
analyzed
Jun 15, 2026, 09:51 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.