zomato-server@1.0.0
Malicious code in zomato-server (npm)
Analysis
zomato-server@1.0.0 is a combosquat package that exfiltrates system information and environment variables at install time. The preinstall hook runs curl to POST the victim's hostname, username, current working directory, and all environment variables (base64-encoded) to the attacker-controlled callback host d8s0b82plbq3u5sb2vo0sb3a9obr4yjt7[.]oast[.]site at path /install/<base64-package-name>. The preuninstall hook similarly sends the hostname to /uninstall/zomato-server. Environment variable exfiltration captures credentials such as NPM_TOKEN, GITHUB_TOKEN, AWS keys, and CI/CD secrets. The package contains only a stub index.js with no real functionality.
- analyzed by
- Leitwacht
- first seen
- Jun 21, 2026, 03:44 PM
- analyzed
- Jun 21, 2026, 03:45 PM
Related advisories
- hex-conv-ae7a@1.0.0
- vaults-monitor-cron@999.0.0
- unreal-horde-dashboard@99999.0.0
- hyperpure@1.0.0
- aikaf668897@1.0.3
- aikaf6688812@1.0.3
- yian666aikf@1.0.3
- @dxcl/http-common-js@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.