vega-lite-next@19.2.1
Malicious code in vega-lite-next (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
vega-lite-next typosquats the vega-lite charting library name. On npm install, the preinstall script (node index.js) collects system information — hostname, platform, architecture, home directory, username, user/group IDs, shell, OS type and release, memory, CPU count — and executes the whoami and id commands. All data is exfiltrated as a JSON POST to hxxps://kbztayu6auucui8s9ucz2mujkaq1er2g[.]oastify[.]com/detox56, a Burp Collaborator-style exfiltration endpoint. The package also bundles an Instagram follow-requests data dump as filler content.
- analyzed by
- Leitwacht
- first seen
- Jun 30, 2026, 03:00 PM
- analyzed
- Jun 30, 2026, 03:01 PM
Related advisories
- @uwr/colors@1.3.6
- ddok-modal@1.0.0
- ripshakti1@81.0.0
- ripshakti@80.0.0
- anthropic-toolkit@0.2.0
- ts-linting-builder@2.1.2
- red-bull-venue-tools@19.2.1
- ts-lint-builders-v2.1@2.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.