airkey-mfa-react@20.0.1
Malicious code in airkey-mfa-react (npm)
Analysis
The package airkey-mfa-react@20.0.1 runs a preinstall hook that executes index.js. This script collects system reconnaissance data — hostname, platform, architecture, home directory, username, UID, GID, shell, OS type/release, CPU count, whoami output, id output, and current working directory — and POSTs it as JSON to the attacker-controlled endpoint hxxps://s70v1tcmg3npuykzzok5t0tdz45vtlha[.]oastify[.]com/detox56. The package has no repository, no description, and its high version number on first publish is consistent with a dependency-confusion or combosquat attack.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 05:35 AM
- analyzed
- Jul 7, 2026, 05:35 AM
Related advisories
- next-locomotive-init@1.0.0
- @digiptf/common@99.99.99
- pinokio-redis@1.0.127
- zredis-typed@1.0.127
- @bobfrankston/gcal@0.1.68
- @adobesign/as-dev-tools@99.9.10
- zod-pino434@1.0.127
- debugcli@4.3.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.