dttfdsdee@1.0.1
Malicious code in dttfdsdee (npm)
Analysis
On package install, the postinstall lifecycle hook executes a curl command that recursively lists the contents of the /data/ directory ($(ls -laR /data/)) and POSTs the output as the request body to a remote host at 3dhd6wwmusbh04m22igmzvb4hvnmblza[.]oastify[.]com via HTTP. The oastify[.]com domain is an out-of-band application security testing (OAST) callback server operated as an exfiltration sink. This reconnaissance payload allows the attacker to confirm execution on the target and map filesystem contents under /data/. The package's published source code (index.js) contains benign string utility functions (camelToKebab, slugify, truncate, etc.) that serve as a decoy; the malicious behaviour is entirely in the postinstall hook defined in package.json.
- analyzed by
- Leitwacht
- first seen
- Jun 26, 2026, 03:02 AM
- analyzed
- Jun 26, 2026, 03:03 AM
Related advisories
- dddooo@1.0.0
- easy-string-kit232@1.0.8
- react-campaign-optimizer@1.0.0
- hyperpure-core@1.0.0
- zomato-config@1.0.0
- zomato-sushi@1.0.0
- blinkit-core@1.0.0
- zomato-logger@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.