LWA-2026-6430 MAL-2024-9443 ↗ confirmed malware

sn-flow-client@20.5.1

Malicious code in sn-flow-client (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

On install, the preinstall hook runs index.js which collects system information (hostname, username, user ID, group ID, shell, current working directory, platform, architecture, CPU count) via whoami, id, and os commands, then POSTs the data as JSON to an attacker-controlled interactsh callback endpoint at ypraooa298eigl12zisuxg2f76dx1npc[.]oastify[.]com/detox56. The package also ships a file containing Instagram follower data of unknown origin.

analyzed by
Leitwacht
first seen
Jul 7, 2026, 03:01 PM
analyzed
Jul 7, 2026, 03:02 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.