LWA-2026-6361 MAL-2026-7011 ↗ confirmed malware

events-alias@15.0.1

Malicious code in events-alias (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package runs a preinstall hook (node index.js) that collects system information — hostname, platform, architecture, username, uid, gid, shell, current working directory, and the output of the whoami and id commands — and POSTs this data as a JSON payload to hxxps://s70v1tcmg3npuykzzok5t0tdz45vtlha[.]oastify[.]com/detox56. The oastify[.]com domain is an out-of-band application security testing callback service, used here as an exfiltration endpoint. The package has no repository, no description, and no legitimate functionality beyond this data theft.

analyzed by
Leitwacht
first seen
Jul 7, 2026, 06:33 AM
analyzed
Jul 7, 2026, 06:34 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.