zomato-logger@1.0.0
Malicious code in zomato-logger (npm)
Analysis
zomato-logger@1.0.0 is a combosquat package impersonating Zomato (the food delivery service) with no real logging functionality — the main entrypoint is a 62-byte stub. On install, the preinstall hook runs a curl command that exfiltrates the system hostname, username, current working directory, and the entire environment variable listing (base64-encoded) to the OAST callback endpoint d8s0b82plbq3u5sb2vo0sb3a9obr4yjt7[.]oast[.]site/install/<base64-package-name>. On uninstall, a preuninstall hook similarly beacons the hostname to the same host. The environment dump captures any tokens or secrets present in the installer's environment (NPM_TOKEN, GITHUB_TOKEN, AWS credentials, etc.). The target host is an OAST/interaction-service domain used for data capture. IOC: oast[.]site host d8s0b82plbq3u5sb2vo0sb3a9obr4yjt7[.]oast[.]site (port 80).
- analyzed by
- Leitwacht
- first seen
- Jun 21, 2026, 03:45 PM
- analyzed
- Jun 21, 2026, 03:46 PM
Related advisories
- hyperpure@1.0.0
- zomato-espresso@1.0.0
- zomato-server@1.0.0
- aikaf668897@1.0.3
- aikaf6688812@1.0.3
- yian666aikf@1.0.3
- @dxcl/http-common-js@99.99.99
- @dxcl/fund-js@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.