consumerweb@2200.4.2
Malicious code in consumerweb (npm)
Analysis
consumerweb@2200.4.2 is a dependency-confusion/trojanized package that exfiltrates host fingerprint data to an oastify callback domain. On install, its preinstall and postinstall hooks both run index.js, which collects the hostname, home directory path, username, DNS resolver addresses, current working directory, and the package.json contents. This data is exfiltrated via two channels: (1) a DNS lookup to a subdomain of bvfmpadujgjgmbtzeibi1n3vi1psox11k[.]oast[.]fun encoded with the hostname and a hash of the collected data; (2) a HTTPS POST of the full data to hxxps://bvfmpadujgjgmbtzeibi1n3vi1psox11k[.]oast[.]fun/. The package has no repository, no README, and uses an unrealistic version number (2200.4.2) consistent with dependency-confusion attacks.
- analyzed by
- Leitwacht
- first seen
- Jul 1, 2026, 06:47 AM
- analyzed
- Jul 1, 2026, 06:54 AM
Related advisories
- ecto-cargo-wk1tm59a@99.0.0
- cursed-modules@999.0.0
- auth-next-gen@1.6.29
- vega-lite-next@19.2.1
- @uwr/colors@1.3.6
- ddok-modal@1.0.0
- ripshakti1@81.0.0
- ripshakti@80.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.