LWA-2026-5818 MAL-2026-6249 ↗ confirmed malware

blinkit-core@1.0.0

Malicious code in blinkit-core (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The preinstall hook exfiltrates the installer's hostname, username, current working directory, and ALL environment variables (base64-encoded via `env | base64 -w0`) to `d8s0b82plbq3u5sb2vo0sb3a9obr4yjt7[.]oast[.]site/install/<base64-package-name>` via curl over HTTP. A preuninstall hook also sends the hostname to `d8s0b82plbq3u5sb2vo0sb3a9obr4yjt7[.]oast[.]site/uninstall/blinkit-core`. The package's `index.js` is a 61-byte stub exporting only name and version; the hooks are the entire payload, designed to capture npm tokens, GitHub tokens, cloud credentials, and any other secrets present in the shell environment at install time.

analyzed by
Leitwacht
first seen
Jun 21, 2026, 03:45 PM
analyzed
Jun 21, 2026, 03:46 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.