zomato-espresso@1.0.0
Malicious code in zomato-espresso (npm)
T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel
Analysis
zomato-espresso@1.0.0 is a combosquat impersonating a real food-delivery company. The package contains no functional code — only a stub index.js — and uses the preinstall lifecycle hook to exfiltrate the hostname, username, current working directory, and all environment variables (base64-encoded) via curl to d8s0b82plbq3u5sb2vo0sb3a9obr4yjt7[.]oast[.]site. A preuninstall hook additionally exfiltrates the hostname to the same domain. The environment variable exfiltration captures any tokens (npm, GitHub, AWS, etc.) present in the installer's shell environment.
- analyzed by
- Leitwacht
- first seen
- Jun 21, 2026, 03:44 PM
- analyzed
- Jun 21, 2026, 03:45 PM
Related advisories
- zomato-server@1.0.0
- aikaf668897@1.0.3
- aikaf6688812@1.0.3
- yian666aikf@1.0.3
- @dxcl/http-common-js@99.99.99
- @dxcl/fund-js@99.99.99
- @dxcl/indicators-js@99.99.99
- @dxcl/transaction-js@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.