LWA-2026-5813 MAL-2026-6253 ↗ confirmed malware

zomato-server@1.0.0

Malicious code in zomato-server (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.004 · Unix ShellT1082 · System Information DiscoveryT1552 · Unsecured CredentialsT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

zomato-server@1.0.0 is a combosquat package that exfiltrates system information and environment variables at install time. The preinstall hook runs curl to POST the victim's hostname, username, current working directory, and all environment variables (base64-encoded) to the attacker-controlled callback host d8s0b82plbq3u5sb2vo0sb3a9obr4yjt7[.]oast[.]site at path /install/<base64-package-name>. The preuninstall hook similarly sends the hostname to /uninstall/zomato-server. Environment variable exfiltration captures credentials such as NPM_TOKEN, GITHUB_TOKEN, AWS keys, and CI/CD secrets. The package contains only a stub index.js with no real functionality.

analyzed by
Leitwacht
first seen
Jun 21, 2026, 03:44 PM
analyzed
Jun 21, 2026, 03:45 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.