LWA-2026-5776 MAL-2026-6485 ↗ confirmed malware

starship-timeline@1.0.1

Malicious code in starship-timeline (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1033 · System Owner/User DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

starship-timeline@1.0.1 runs a preinstall hook (node index.js) that reads /etc/passwd, /etc/hosts, hostname, username, home directory, DNS servers, and the installation path, then POSTs all collected data via HTTPS to a Burp Collaborator endpoint (5tziqozihbss8jg955ez91bycpij69uy[.]oastify[.]com). The package has no declared purpose (empty description) and the hook executes automatically on npm install.

analyzed by
Leitwacht
first seen
Jun 19, 2026, 04:55 PM
analyzed
Jun 19, 2026, 04:55 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.