LWA-2026-5736 MAL-2026-6143 ↗ confirmed malware

node-vfs-polyfill@2.0.5

Malicious code in node-vfs-polyfill (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1057 · Process DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

node-vfs-polyfill is a dependency-confusion supply-chain attack. On npm install, its postinstall.js hook: (1) queries ip-api[.]com/json/ for the victim's public IP and full geolocation (country, city, ISP, ASN, lat/lon, proxy/hosting status); (2) runs ps aux to collect the full process list; (3) reads system info (hostname, platform, CPU cores, memory, network interfaces, disk); (4) harvests ALL environment variables from the CI/build environment, targeting over 50 sensitive-key patterns including NPM_TOKEN, GITHUB_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, ANTHROPIC_API_KEY, OPENAI_API_KEY, STRIPE_SECRET_KEY, SLACK_TOKEN, TWILIO_AUTH_TOKEN, SENDGRID_API_KEY, and DOCKER_PASSWORD; (5) POSTs the entire payload (hostname, geo, process list, all env vars, disk info, network config, uptime) as JSON to rni4z9qkil62r9dcwosokhtgo7u9i76w[.]oastify[.]com port 80. The HTTP request carries X-Poc-Type: dependency-confusion, X-Poc-Package: node-vfs-polyfill, and X-Poc-Version: 2.0.5 headers. The C2 endpoint is an oastify[.]com (Burp Collaborator) URL.

analyzed by
Leitwacht
first seen
Jun 18, 2026, 06:08 PM
analyzed
Jun 18, 2026, 06:08 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.