llm-traces-app@1.0.1
Malicious code in llm-traces-app (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1033 · System Owner/User DiscoveryT1005 · Data from Local SystemT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
On npm install, the preinstall hook executes index.js which collects system information (hostname, home directory, username, DNS servers) and reads /etc/passwd and /etc/hosts, then exfiltrates the data via HTTPS POST to ltiyq4zyhrs88zgp5lef9hbec5i46uuj[.]oastify[.]com (Burp Collaborator domain) on port 443.
- analyzed by
- Leitwacht
- first seen
- Jun 20, 2026, 11:32 AM
- analyzed
- Jun 20, 2026, 11:32 AM
Related advisories
- starship-timeline@1.0.1
- cardano-addresses-docs@1.0.1
- streak-metrics-math@1.0.1
- streak-metrics-core@1.0.0
- shift-v4-sdk@1.0.5
- shift-sdk-v5@5.0.1
- ohcm-culture-formatting@5.0.0
- atlasora-utils@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.