afterpay-sdk-example-server@1.2.1
Malicious code in afterpay-sdk-example-server (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
Package afterpay-sdk-example-server (a combosquat name on the Afterpay payment brand) runs a preinstall hook that executes index.js during npm install. The script collects system reconnaissance data — hostname, username, home directory path, DNS server list, and the full contents of /etc/passwd and /etc/hosts — then exfiltrates them via HTTPS POST to a Burp Collaborator server at xqrangwae3pk5bd12xbr6t8q9hfc32rr[.]oastify[.]com. This is a system-information beacon designed to gather environment intelligence from the victim's machine.
- analyzed by
- Leitwacht
- first seen
- Jun 19, 2026, 05:20 PM
- analyzed
- Jun 19, 2026, 05:20 PM
Related advisories
- starship-timeline@1.0.1
- dbt-language-server@1.0.1
- simplisafe-gatsby@1.0.1
- parket-flow@3.0.1
- ts-eslinter@1.0.0
- @withgoogle/stitch-sdk@0.1.1
- new-ts-helper@9.0.2
- yianzzkf6687@1.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.