ppt-creator@1.0.0
Malicious code in ppt-creator (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
ppt-creator@1.0.0 is a malicious package that exfiltrates system data at install time. The preinstall hook (node index.js) runs during npm install, collecting the victim's hostname, username, home directory path, DNS server list, and the contents of /etc/passwd and /etc/hosts. This data is sent via HTTPS POST to 3z3l99x7vp8us6lzqm575hfh58bzzqnf[.]oastify[.]com (a Burp Collaborator endpoint). The package contains no legitimate functionality.
- analyzed by
- Leitwacht
- first seen
- Jun 23, 2026, 08:03 PM
- analyzed
- Jun 23, 2026, 08:03 PM
Related advisories
- ollama-helpers@0.2.1
- date-format-helper2@1.0.4
- block-slot@1.0.9
- kdrive-utils@99.9.9
- pino-zod@1.0.121
- zod-pino@1.0.122
- search-from-search@999.99.99
- hunsterx-package@7.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.