LWA-2026-5997 MAL-2026-6514 ↗ confirmed malware

dtxtools@1.0.0

Malicious code in dtxtools (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

dtxtools@1.0.0 is a trojanized string-utility library. On npm install, its postinstall hook scans the filesystem for database client binaries (mysql, mongo, mongosh, psql, redis-cli, sqlite3, elasticsearch) and POSTs the findings to hxxp://3dhd6wwmusbh04m22igmzvb4hvnmblza[.]oastify[.]com/data/db_clients_check[.]txt. The hook performs this via a find command piped to curl exfiltration. The package's index.js contains benign string helpers (camelToKebab, slugify, etc.) as a decoy; the malicious behaviour runs from the lifecycle hook at install time regardless.

analyzed by
Leitwacht
first seen
Jun 26, 2026, 08:50 AM
analyzed
Jun 26, 2026, 08:51 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.