easy-string-kit232@1.0.8
Malicious code in easy-string-kit232 (npm)
T1059.004 · Unix ShellT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
easy-string-kit232@1.0.8 contains a postinstall hook that exfiltrates system data. Upon install, the script runs `ls -la /data/logs/` and POSTs the directory listing to an attacker-controlled host at `hxxp://3dhd6wwmusbh04m22igmzvb4hvnmblza[.]oastify[.]com/data`. The package publishes legitimate-looking string utility functions (camelCase/kebab-case conversion, truncation, slugify) as a cover while the install hook performs system reconnaissance.
- analyzed by
- Leitwacht
- first seen
- Jun 25, 2026, 09:56 AM
- analyzed
- Jun 25, 2026, 09:57 AM
Related advisories
- react-campaign-optimizer@1.0.0
- hyperpure-core@1.0.0
- zomato-config@1.0.0
- zomato-sushi@1.0.0
- blinkit-core@1.0.0
- zomato-logger@1.0.0
- hyperpure@1.0.0
- zomato-espresso@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.