LWA-2026-6360 MAL-2026-6910 ↗ confirmed malware

zluri-ad-connector@9.9.9

Malicious code in zluri-ad-connector (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package zluri-ad-connector@9.9.9 is a trojanized clone (combosquat on the Zluri identity platform name, version 9.9.9) with no actual AD connector functionality. Its preinstall hook (package/scripts.preinstall: "node index.js") executes package/index.js, which harvests environment variables matching sensitive key patterns (npm_token, github_token, aws_access_key_id, aws_secret_access_key, aws_session_token, ci/circle/travis/gitlab tokens, passwords, API keys, credentials) and collects system fingerprint data (hostname, homedir, username, OS type/release, DNS servers, PATH, Node.js version, npm context). All collected data is serialized and POSTed via HTTPS to y543452sgo96xsasfdr72ms4rvxmld92[.]oastify[.]com:443. Errors are silently swallowed to avoid detection. The package has no repository, no actual connector code, and its sole purpose is credential exfiltration on install.

analyzed by
Leitwacht
first seen
Jul 7, 2026, 06:19 AM
analyzed
Jul 7, 2026, 06:20 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.