zluri-ad-connector@9.9.9
Malicious code in zluri-ad-connector (npm)
Analysis
The package zluri-ad-connector@9.9.9 is a trojanized clone (combosquat on the Zluri identity platform name, version 9.9.9) with no actual AD connector functionality. Its preinstall hook (package/scripts.preinstall: "node index.js") executes package/index.js, which harvests environment variables matching sensitive key patterns (npm_token, github_token, aws_access_key_id, aws_secret_access_key, aws_session_token, ci/circle/travis/gitlab tokens, passwords, API keys, credentials) and collects system fingerprint data (hostname, homedir, username, OS type/release, DNS servers, PATH, Node.js version, npm context). All collected data is serialized and POSTed via HTTPS to y543452sgo96xsasfdr72ms4rvxmld92[.]oastify[.]com:443. Errors are silently swallowed to avoid detection. The package has no repository, no actual connector code, and its sole purpose is credential exfiltration on install.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 06:19 AM
- analyzed
- Jul 7, 2026, 06:20 AM
Related advisories
- pinokio-redis@1.0.127
- @bobfrankston/gcal@0.1.68
- @bobfrankston/mailx-store-web@0.1.35
- debugcli@4.3.4
- polymarket-trader-apis@0.1.0
- polymarket-apis@1.1.0
- yiyuan-api@1.0.3
- polygon-gamma-apis@1.5.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.