LWA-2026-5720 MAL-2026-6127 ↗ confirmed malware

@onum-releases/utils@1.0.1

Malicious code in @onum-releases/utils (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Package @onum-releases/utils@1.0.1 runs a hostname reconnaissance beacon when required in Node.js. The index.js file reads os.hostname(), constructs the subdomain 'utils.<hostname>.200majoeu01dk02xnjdajro1isojc90y[.]oastify[.]com', and issues an HTTPS GET to '/utils' on that host — exfiltrating the hostname to an attacker-controlled OAST/intercept-style callback domain. The package description falsely claims "no runtime payload."

analyzed by
Leitwacht
first seen
Jun 18, 2026, 12:08 PM
analyzed
Jun 18, 2026, 12:10 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.