cardano-addresses-docs@1.0.1
Malicious code in cardano-addresses-docs (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1033 · System Owner/User DiscoveryT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
Package cardano-addresses-docs@1.0.1 runs a data-exfiltration beacon on npm install. The preinstall script executes index.js, which reads /etc/passwd, /etc/hosts, hostname, homedir, username, and DNS server configuration from the installer's system, then POSTs the collected data as JSON to swsusmhg43tobo96re8dwn0vomudi46t[.]oastify[.]com via HTTPS. The domain is a Burp Collaborator callback endpoint commonly used in penetration testing and by attackers to receive exfiltrated data.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 11:09 AM
- analyzed
- Jun 15, 2026, 11:11 AM
Related advisories
- streak-metrics-math@1.0.1
- streak-metrics-core@1.0.0
- shift-v4-sdk@1.0.5
- shift-sdk-v5@5.0.1
- ohcm-culture-formatting@5.0.0
- llm-traces-app@1.0.1
- starship-timeline@1.0.1
- umi-preset-rce-jytest@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.