rio-design-tokens@99.99.99
Malicious code in rio-design-tokens (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
A dependency-confusion package (version 99.99.99, no repository) that exfiltrates system metadata on install. The preinstall hook runs index.js, which collects the hostname, home directory path, username, DNS server addresses, current working directory, and the package.json contents, then POSTs this data to gi2dq59ku7d5xyjnjhuwpyr1gsmjaayz[.]oastify[.]com over HTTPS.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 11:03 PM
- analyzed
- Jul 7, 2026, 11:04 PM
Related advisories
- hello244b@1.0.0
- sn-flow-client@20.5.1
- mcp-server-pg@0.2.0
- motion-pull@2.3.5
- configration@2.3.5
- chai-smart@2.3.5
- express-mongo-limit@2.0.1
- events-alias@15.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.