LWA-2026-5721 MAL-2026-6123 ↗ confirmed malware

@onum-releases/auth@1.0.1

Malicious code in @onum-releases/auth (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols

Analysis

This package falsely describes itself as having "no runtime payload" but index.js fires an active hostname beacon on require(). When the package is imported, it reads os.hostname(), transforms it, and sends an HTTPS GET request to a subdomain constructed as auth.{sanitized-hostname}.200majoeu01dk02xnjdajro1isojc90y[.]oastify[.]com/auth. This discloses the installer's machine hostname to an external callback server controlled by the package author.

analyzed by
Leitwacht
first seen
Jun 18, 2026, 12:08 PM
analyzed
Jun 18, 2026, 12:09 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.