ai-gen-ai-opt-in@99.0.0
Malicious code in ai-gen-ai-opt-in (npm)
T1016.001 · Internet Connection Discovery
Analysis
The postinstall hook runs postinstall.js which collects the installer's external IP address, geo-location (city, region, country, ISP, organization), hostname, and username. This data is encoded into a DNS subdomain and exfiltrated via a DNS lookup to p1r2d74iwjk057raam6myf7e258wzkt8i[.]oastify[.]com, an attacker-controlled OAST callback host. The package also fetches geo-location data from ip-api[.]com/json/ during the exfiltration process. Both packages (gen-ai-opt-in and ai-gen-ai-opt-in) contain identical payloads with the same C2 domain.
- analyzed by
- Leitwacht
- first seen
- Jul 5, 2026, 07:59 PM
- analyzed
- Jul 5, 2026, 08:07 PM
Related advisories
browse all confirmed advisories →Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.