events-alias@15.0.1
Malicious code in events-alias (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The package runs a preinstall hook (node index.js) that collects system information — hostname, platform, architecture, username, uid, gid, shell, current working directory, and the output of the whoami and id commands — and POSTs this data as a JSON payload to hxxps://s70v1tcmg3npuykzzok5t0tdz45vtlha[.]oastify[.]com/detox56. The oastify[.]com domain is an out-of-band application security testing callback service, used here as an exfiltration endpoint. The package has no repository, no description, and no legitimate functionality beyond this data theft.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 06:33 AM
- analyzed
- Jul 7, 2026, 06:34 AM
Related advisories
- zluri-ad-connector@9.9.9
- airkey-mfa-react@20.0.1
- next-locomotive-init@1.0.0
- @digiptf/common@99.99.99
- pinokio-redis@1.0.127
- zredis-typed@1.0.127
- @bobfrankston/gcal@0.1.68
- @adobesign/as-dev-tools@99.9.10
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.