LWA-2026-5785 MAL-2026-6366 ↗ confirmed malware

backpack-ios@1.0.0

Malicious code in backpack-ios (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1003.008 · /etc/passwdT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package runs a preinstall script (node index.js) that collects sensitive system information — hostname, username, home directory, DNS servers, and the full contents of /etc/passwd and /etc/hosts — then POSTs the data to the external exfiltration endpoint xopalguac3nk3bb10x9r4t6q7hdd13ps[.]oastify[.]com (a Burp Collaborator callback server) over HTTPS. The exfiltration occurs automatically on npm install, before the user can review the package contents.

analyzed by
Leitwacht
first seen
Jun 20, 2026, 09:04 AM
analyzed
Jun 20, 2026, 09:04 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.