zomato-core@1.0.0
Malicious code in zomato-core (npm)
Analysis
The package zomato-core@1.0.0 impersonates the Zomato brand with a combosquat name. Its preinstall hook collects the hostname, username, current working directory, and the full process environment (base64-encoded — capturing any NPM/GitHub/AWS tokens present at install time) and sends them to hxxp://d8s0b82plbq3u5sb2vo0sb3a9obr4yjt7[.]oast[.]site/install/<base64-pkgname> via HTTP POST. A preuninstall hook additionally beacons the hostname to hxxp://d8s0b82plbq3u5sb2vo0sb3a9obr4yjt7[.]oast[.]site/uninstall/zomato-core. The actual index.js is a 60-byte stub with no functional code, confirming the package exists only to steal environment secrets and system metadata.
- analyzed by
- Leitwacht
- first seen
- Jun 21, 2026, 03:44 PM
- analyzed
- Jun 21, 2026, 03:45 PM
Related advisories
- zomato-mcp@1.0.0
- @variational/common-ui@99.0.0
- @npmresearch3/metrics-probe-dfda@1.0.0
- metrics-probe-9b4c@1.0.0
- @velkov/viem@2.53.1
- local-ip-helper@0.1.0
- ts-bn-lint-helper@3.1.19
- atlasora-client@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.