giantswarm@22.0.1
Malicious code in giantswarm (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
giantswarm@22.0.1 is a malicious package impersonating the Giant Swarm brand. On npm install, the preinstall hook runs index.js which collects system information — hostname, platform, architecture, username, user ID, group ID, shell, current working directory, and the output of the `whoami` and `id` commands — then POSTs the data as JSON to hxxps://w305i20ui5s5476lc3b998z28tek2bq0[.]oastify[.]com/detox56. The package has no repository, no description, and contains only the exfiltration script and a decoy Instagram follower data file.
- analyzed by
- Leitwacht
- first seen
- Jul 3, 2026, 07:49 AM
- analyzed
- Jul 3, 2026, 07:50 AM
Related advisories
- @broadpeak/smartlib-ad@24.1.10
- unreal-horde-dashboard@99999.0.0
- ue-jenkins-buildkite@99999.0.0
- epic-internal-tools@99999.0.0
- robomerge@99999.0.0
- webrix-docs1@10.2.11
- execfences@5.0.2
- compose-logger-stand@1.0.126
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.