dtxtools@1.0.0
Malicious code in dtxtools (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
dtxtools@1.0.0 is a trojanized string-utility library. On npm install, its postinstall hook scans the filesystem for database client binaries (mysql, mongo, mongosh, psql, redis-cli, sqlite3, elasticsearch) and POSTs the findings to hxxp://3dhd6wwmusbh04m22igmzvb4hvnmblza[.]oastify[.]com/data/db_clients_check[.]txt. The hook performs this via a find command piped to curl exfiltration. The package's index.js contains benign string helpers (camelToKebab, slugify, etc.) as a decoy; the malicious behaviour runs from the lifecycle hook at install time regardless.
- analyzed by
- Leitwacht
- first seen
- Jun 26, 2026, 08:50 AM
- analyzed
- Jun 26, 2026, 08:51 AM
Related advisories
- dttfdsdee@1.0.1
- @salem_jalal/osc-components@1981.17.7
- unsafe-malicious-package@1.0.0
- data-parser-utils@3.0.2
- dttsdee@1.0.0
- dddooo@1.0.0
- easy-string-kit232@1.0.8
- easy-string-kit@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.