vend-utilities@14.12.11
Malicious code in vend-utilities (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1195.002 · Compromise Software Supply Chain
Analysis
vend-utilities@14.12.11 executes a host reconnaissance beacon at install time. The preinstall hook runs index.js, which collects system information (hostname, platform, architecture, home directory, username, uid/gid/shell, OS type/release, memory, CPU count, whoami output, id output, current working directory) and exfiltrates it via an HTTPS POST to the C2 endpoint 6cjy9tle5weq8pr6m8r5znzd349vxmlb[.]oastify[.]com/detox56. The package also ships a large Instagram username list as filler (file 'i'), unrelated to the malicious payload.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 05:28 PM
- analyzed
- Jun 15, 2026, 05:29 PM
Related advisories
- vfat-tools@2.0.0
- typescript-util-core@7.1.5
- vault-strategies@999.0.0
- var-helper-kit@1.0.1
- sam-package@1.0.1
- @resolvx/core@2.4.2
- flow-lending-sdk@9.9.9
- bodega-sdk@9.9.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.