LWA-2026-6263 MAL-2026-10081 ↗ confirmed malware

webrix-docs1@10.2.11

Malicious code in webrix-docs1 (npm)

T1195 · Supply Chain CompromiseT1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel

Analysis

The package's preinstall hook (node index.js) runs automatically on install. It collects system information — hostname, platform, architecture, username, user ID, group ID, shell, OS type, release, total and free memory, CPU count, whoami, id, and current working directory — and POSTs the data as JSON to the external host c7kfuaf25guwigaz6r03kxet0k6bu3is[.]oastify[.]com at path /detox56. The package has no description, no repository URL, and no legitimate functionality.

analyzed by
Leitwacht
first seen
Jul 2, 2026, 03:49 PM
analyzed
Jul 2, 2026, 03:50 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.