webrix-docs1@10.2.11
Malicious code in webrix-docs1 (npm)
T1195 · Supply Chain CompromiseT1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 Channel
Analysis
The package's preinstall hook (node index.js) runs automatically on install. It collects system information — hostname, platform, architecture, username, user ID, group ID, shell, OS type, release, total and free memory, CPU count, whoami, id, and current working directory — and POSTs the data as JSON to the external host c7kfuaf25guwigaz6r03kxet0k6bu3is[.]oastify[.]com at path /detox56. The package has no description, no repository URL, and no legitimate functionality.
- analyzed by
- Leitwacht
- first seen
- Jul 2, 2026, 03:49 PM
- analyzed
- Jul 2, 2026, 03:50 PM
Related advisories
- lusha-iam-widgets@1.5.2
- driftpin@1.0.0
- ryan-pdf-js@99.9.1
- chai-as-assured@7.1.2
- ollama-helpers@0.2.1
- aikaf668897@1.0.3
- wm-idp-sdk@1.2.0
- wac-atl-context@99.9.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.