oauth-connect@0.1.1
Malicious code in oauth-connect (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1041 · Exfiltration Over C2 Channel
Analysis
The package oauth-connect@0.1.1 executes a preinstall script (node index.js) that performs system reconnaissance on the installer's machine and exfiltrates the data. It collects: hostname, username, home directory, DNS server list, the contents of /etc/passwd, and the contents of /etc/hosts. All collected data is sent via HTTPS POST to f3js0y9srl22itqjffo9jbl8mzswgm4b[.]oastify[.]com (a Burp Collaborator exfiltration endpoint). The package has no legitimate functionality and only exists to exfiltrate system information upon installation.
- analyzed by
- Leitwacht
- first seen
- Jun 20, 2026, 09:34 AM
- analyzed
- Jun 20, 2026, 09:34 AM
Related advisories
- log-taker1@0.1.0
- ts-bn-proto@5.8.1
- parket-flow@3.0.1
- ts-eslinter@1.0.0
- new-ts-helper@9.0.2
- new-helper@5.8.1
- ts-big-ecro@3.8.1
- stitch-design@0.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.