LWA-2026-6337 confirmed malware
gen-ai-opt-in@99.0.1
Malicious code in gen-ai-opt-in (npm)
T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages
Analysis
The postinstall hook runs postinstall.js which collects the installer's external IP address, geo-location (city, region, country, ISP, organization), hostname, and username. This data is encoded into a DNS subdomain and exfiltrated via a DNS lookup to p1r2d74iwjk057raam6myf7e258wzkt8i[.]oastify[.]com, an attacker-controlled OAST callback host. The package also fetches geo-location data from ip-api[.]com/json/ during the exfiltration process. Both packages (gen-ai-opt-in and ai-gen-ai-opt-in) contain identical payloads with the same C2 domain.
- analyzed by
- Leitwacht
- first seen
- Jul 5, 2026, 08:06 PM
- analyzed
- Jul 5, 2026, 08:07 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.