simplisafe-gatsby@1.0.1
Malicious code in simplisafe-gatsby (npm)
Analysis
simplisafe-gatsby@1.0.1 runs a preinstall hook that executes index.js. During npm install it collects the victim's hostname, home directory, username, DNS server addresses, and reads the contents of /etc/passwd and /etc/hosts from the filesystem. All collected data is exfiltrated via HTTPS POST to the Burp Collaborator instance xpqamgvad3ok4bc11xar5t7q8he820qp[.]oastify[.]com (port 443, path /). The package has no repository, no description, and no legitimate purpose — it is a system-reconnaissance and credential-discovery implant that activates automatically before the package even finishes installing.
- analyzed by
- Leitwacht
- first seen
- Jun 19, 2026, 03:17 PM
- analyzed
- Jun 19, 2026, 03:17 PM
Related advisories
- array-sort-helper@1.0.0
- text-line-parser@1.0.0
- date-sanitize-helper@1.0.0
- basic-vite@1.0.0
- parket-flow@3.0.1
- ts-eslinter@1.0.0
- @withgoogle/stitch-sdk@0.1.1
- new-ts-helper@9.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.