dtxto1ols@1.0.2
Malicious code in dtxto1ols (npm)
Analysis
A trojanized string-utility package. The published source code (index.js) contains benign functions (camelToKebab, slugify, truncate, etc.) as camouflage, while the postinstall hook performs host reconnaissance and data exfiltration. On install, the shell script scans the filesystem for database client binaries (mysql, mongo, mongosh, psql, redis-cli, sqlite3, elasticsearch) and writes the results to /data/db_clients_check.txt. It then sends the data via HTTP POST to the external endpoint hxxp://3dhd6wwmusbh04m22igmzvb4hvnmblza[.]oastify[.]com/data/db_clients_check[.]txt. The oastify[.]com domain is an attacker-controlled exfiltration callback server. The package has no repository URL and no homepage.
- analyzed by
- Leitwacht
- first seen
- Jun 26, 2026, 09:06 AM
- analyzed
- Jun 26, 2026, 09:07 AM
Related advisories
- dttfdsdee@1.0.1
- dddooo@1.0.0
- easy-string-kit232@1.0.8
- react-campaign-optimizer@1.0.0
- hyperpure-core@1.0.0
- zomato-config@1.0.0
- zomato-sushi@1.0.0
- blinkit-core@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.