LWA-2026-5773 MAL-2026-6379 ↗ confirmed malware

simplisafe-gatsby@1.0.1

Malicious code in simplisafe-gatsby (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1087.001 · Local AccountT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

simplisafe-gatsby@1.0.1 runs a preinstall hook that executes index.js. During npm install it collects the victim's hostname, home directory, username, DNS server addresses, and reads the contents of /etc/passwd and /etc/hosts from the filesystem. All collected data is exfiltrated via HTTPS POST to the Burp Collaborator instance xpqamgvad3ok4bc11xar5t7q8he820qp[.]oastify[.]com (port 443, path /). The package has no repository, no description, and no legitimate purpose — it is a system-reconnaissance and credential-discovery implant that activates automatically before the package even finishes installing.

analyzed by
Leitwacht
first seen
Jun 19, 2026, 03:17 PM
analyzed
Jun 19, 2026, 03:17 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.