LWA-2026-5815 MAL-2026-6269 ↗ confirmed malware

zomato-espresso@1.0.0

Malicious code in zomato-espresso (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel

Analysis

zomato-espresso@1.0.0 is a combosquat impersonating a real food-delivery company. The package contains no functional code — only a stub index.js — and uses the preinstall lifecycle hook to exfiltrate the hostname, username, current working directory, and all environment variables (base64-encoded) via curl to d8s0b82plbq3u5sb2vo0sb3a9obr4yjt7[.]oast[.]site. A preuninstall hook additionally exfiltrates the hostname to the same domain. The environment variable exfiltration captures any tokens (npm, GitHub, AWS, etc.) present in the installer's shell environment.

analyzed by
Leitwacht
first seen
Jun 21, 2026, 03:44 PM
analyzed
Jun 21, 2026, 03:45 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.