starship-timeline@1.0.1
Malicious code in starship-timeline (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1033 · System Owner/User DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
starship-timeline@1.0.1 runs a preinstall hook (node index.js) that reads /etc/passwd, /etc/hosts, hostname, username, home directory, DNS servers, and the installation path, then POSTs all collected data via HTTPS to a Burp Collaborator endpoint (5tziqozihbss8jg955ez91bycpij69uy[.]oastify[.]com). The package has no declared purpose (empty description) and the hook executes automatically on npm install.
- analyzed by
- Leitwacht
- first seen
- Jun 19, 2026, 04:55 PM
- analyzed
- Jun 19, 2026, 04:55 PM
Related advisories
- cardano-addresses-docs@1.0.1
- streak-metrics-math@1.0.1
- streak-metrics-core@1.0.0
- shift-v4-sdk@1.0.5
- shift-sdk-v5@5.0.1
- ohcm-culture-formatting@5.0.0
- llm-traces-app@1.0.1
- dbt-language-server@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.