LWA-2026-6336 MAL-2026-6990 ↗ confirmed malware

ai-gen-ai-opt-in@99.0.0

Malicious code in ai-gen-ai-opt-in (npm)

T1016.001 · Internet Connection Discovery

Analysis

The postinstall hook runs postinstall.js which collects the installer's external IP address, geo-location (city, region, country, ISP, organization), hostname, and username. This data is encoded into a DNS subdomain and exfiltrated via a DNS lookup to p1r2d74iwjk057raam6myf7e258wzkt8i[.]oastify[.]com, an attacker-controlled OAST callback host. The package also fetches geo-location data from ip-api[.]com/json/ during the exfiltration process. Both packages (gen-ai-opt-in and ai-gen-ai-opt-in) contain identical payloads with the same C2 domain.

analyzed by
Leitwacht
first seen
Jul 5, 2026, 07:59 PM
analyzed
Jul 5, 2026, 08:07 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.