LWA-2026-6195 MAL-2026-10181 ↗ confirmed malware

consumerweb@2200.4.2

Malicious code in consumerweb (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1195.002 · Compromise Software Supply Chain

Analysis

consumerweb@2200.4.2 is a dependency-confusion/trojanized package that exfiltrates host fingerprint data to an oastify callback domain. On install, its preinstall and postinstall hooks both run index.js, which collects the hostname, home directory path, username, DNS resolver addresses, current working directory, and the package.json contents. This data is exfiltrated via two channels: (1) a DNS lookup to a subdomain of bvfmpadujgjgmbtzeibi1n3vi1psox11k[.]oast[.]fun encoded with the hostname and a hash of the collected data; (2) a HTTPS POST of the full data to hxxps://bvfmpadujgjgmbtzeibi1n3vi1psox11k[.]oast[.]fun/. The package has no repository, no README, and uses an unrealistic version number (2200.4.2) consistent with dependency-confusion attacks.

analyzed by
Leitwacht
first seen
Jul 1, 2026, 06:47 AM
analyzed
Jul 1, 2026, 06:54 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.