LWA-2026-5534 confirmed malware

xpna-context@1.0.2

Malicious code in xpna-context (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

xpna-context@1.0.2 executes host reconnaissance at install time via its preinstall hook. The hook runs shell commands that transmit the installer's hostname to an attacker-controlled OAST callback server (je15qppk9nkf2oim0q2cty8n5eb6zwnl[.]oastify[.]com). Additionally, a bundled JS file (injex.js) collects the hostname, user info, and all environment variables and POSTs them as JSON to a second endpoint (j3n5fpekyn9fro7mpqrciyxnue05ozco[.]oastify[.]com/Log). This captures any credentials, API keys, or tokens present in the environment variables of the system where the package is installed.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 07:49 AM
analyzed
Jun 16, 2026, 07:50 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.