@onum-releases/auth@1.0.1
Malicious code in @onum-releases/auth (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols
Analysis
This package falsely describes itself as having "no runtime payload" but index.js fires an active hostname beacon on require(). When the package is imported, it reads os.hostname(), transforms it, and sends an HTTPS GET request to a subdomain constructed as auth.{sanitized-hostname}.200majoeu01dk02xnjdajro1isojc90y[.]oastify[.]com/auth. This discloses the installer's machine hostname to an external callback server controlled by the package author.
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 12:08 PM
- analyzed
- Jun 18, 2026, 12:09 PM
Related advisories
- @onum-releases/utils@1.0.1
- @dxcl/http-common-js@99.99.99
- @dxcl/fund-js@99.99.99
- @dxcl/indicators-js@99.99.99
- @dxcl/transaction-js@99.99.99
- @dxcl/user-js@99.99.99
- @dxcl/account-js@99.99.99
- @dxcl/customer-js@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.