ogd-platform@1.0.0
Malicious code in ogd-platform (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
ogd-platform@1.0.0 contains no functional code — only a preinstall lifecycle hook in package.json. On npm install, the hook runs hostname, whoami, and pwd to collect host system information, then exfiltrates this data via curl POST to hxxps://webhook[.]site/1ea0386f-dcc0-4f1b-bdbb-61732d6535fb/ogd-platform (a webhook[.]site endpoint commonly used for data collection).
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 09:50 AM
- analyzed
- Jun 15, 2026, 09:51 AM
Related advisories
- nic-datagov@1.0.0
- typescript-util-core@3.5.0
- ts-relayer-pub@1.0.0
- ts-lint-builds@1.0.5
- 1edtech_lti_dev@1.2.4
- ts-enum-helper@1.0.0
- tiny-string-parser@0.1.2
- hemi-supply-cron@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.