node-vfs-polyfill@2.0.5
Malicious code in node-vfs-polyfill (npm)
Analysis
node-vfs-polyfill is a dependency-confusion supply-chain attack. On npm install, its postinstall.js hook: (1) queries ip-api[.]com/json/ for the victim's public IP and full geolocation (country, city, ISP, ASN, lat/lon, proxy/hosting status); (2) runs ps aux to collect the full process list; (3) reads system info (hostname, platform, CPU cores, memory, network interfaces, disk); (4) harvests ALL environment variables from the CI/build environment, targeting over 50 sensitive-key patterns including NPM_TOKEN, GITHUB_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, ANTHROPIC_API_KEY, OPENAI_API_KEY, STRIPE_SECRET_KEY, SLACK_TOKEN, TWILIO_AUTH_TOKEN, SENDGRID_API_KEY, and DOCKER_PASSWORD; (5) POSTs the entire payload (hostname, geo, process list, all env vars, disk info, network config, uptime) as JSON to rni4z9qkil62r9dcwosokhtgo7u9i76w[.]oastify[.]com port 80. The HTTP request carries X-Poc-Type: dependency-confusion, X-Poc-Package: node-vfs-polyfill, and X-Poc-Version: 2.0.5 headers. The C2 endpoint is an oastify[.]com (Burp Collaborator) URL.
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 06:08 PM
- analyzed
- Jun 18, 2026, 06:08 PM
Related advisories
- stellarfixer@1.0.0
- simple-date-formatter-util-12@1.0.0
- twork-data-services-customer-api-v2-customer-vip-status@20.9.7
- streak-int-lib@1.0.0
- text-line-parser@1.0.0
- date-sanitize-helper@1.0.0
- n8n-nodes-utils-helper@1.0.0
- n8n-nodes-task-runner@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.