@onum-releases/utils@1.0.1
Malicious code in @onum-releases/utils (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
Package @onum-releases/utils@1.0.1 runs a hostname reconnaissance beacon when required in Node.js. The index.js file reads os.hostname(), constructs the subdomain 'utils.<hostname>.200majoeu01dk02xnjdajro1isojc90y[.]oastify[.]com', and issues an HTTPS GET to '/utils' on that host — exfiltrating the hostname to an attacker-controlled OAST/intercept-style callback domain. The package description falsely claims "no runtime payload."
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 12:08 PM
- analyzed
- Jun 18, 2026, 12:10 PM
Related advisories
- @onum-releases/auth@1.0.1
- @dxcl/http-common-js@99.99.99
- @dxcl/fund-js@99.99.99
- @dxcl/transaction-js@99.99.99
- @dxcl/user-js@99.99.99
- @dxcl/account-js@99.99.99
- @dxcl/customer-js@99.99.99
- color-utils-eee0@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.