LWA-2026-5406 MAL-2026-5832 ↗ confirmed malware

vend-utilities@14.12.11

Malicious code in vend-utilities (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1195.002 · Compromise Software Supply Chain

Analysis

vend-utilities@14.12.11 executes a host reconnaissance beacon at install time. The preinstall hook runs index.js, which collects system information (hostname, platform, architecture, home directory, username, uid/gid/shell, OS type/release, memory, CPU count, whoami output, id output, current working directory) and exfiltrates it via an HTTPS POST to the C2 endpoint 6cjy9tle5weq8pr6m8r5znzd349vxmlb[.]oastify[.]com/detox56. The package also ships a large Instagram username list as filler (file 'i'), unrelated to the malicious payload.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 05:28 PM
analyzed
Jun 15, 2026, 05:29 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.