library-explorer@25.2.1
Malicious code in library-explorer (npm)
Analysis
library-explorer@25.2.1 runs a postinstall/preinstall hook that executes index.js during npm install. The script collects system information (hostname, platform, architecture, username, user ID, group ID, shell, home directory, total/free memory, CPU count, current working directory, and the output of the 'whoami' and 'id' shell commands) and sends it as a JSON POST to hxxps://bgvge0daqrvkonl6x9qrx553ruxllb90[.]oastify[.]com/detox56. The oastify[.]com domain is an OAST/Interact.sh callback endpoint, indicating the collected data is exfiltrated to an attacker-controlled listener. The package has no repository or description, and its tarball also contains a 10KB Instagram follow-request data dump as padding.
- analyzed by
- Leitwacht
- first seen
- Jun 29, 2026, 09:10 AM
- analyzed
- Jun 29, 2026, 09:11 AM
Related advisories
- @digitalcnzz/embedded-sdk@1.0.7
- rebrandly-domains-digger@9999.0.0
- ai-explain@0.3.4
- anthropic-internal-tools@1.0.0
- friendly-greeter-demo@1.0.10
- livekit-agents@0.3.0
- ts-ankle@1.1.0
- @epsteinlovekids483/crossmint-wallets-sdk-pentest@1.0.0-pentest
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.