LWA-2026-6454 confirmed malware
@comcastdevxplatforms/plugin-tenancyinformation@28.1.1
Malicious code in @comcastdevxplatforms/plugin-tenancyinformation (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
@comcastdevxplatforms/plugin-tenancyinformation is a combosquat package targeting Comcast's internal namespace. On npm install, the preinstall hook executes index.js which collects system information (hostname, platform, architecture, username, uid, gid, shell, whoami output, current working directory) and exfiltrates it as a JSON POST to rsnchacyin4dnjv0oc8prrwn1e77vzjo[.]oastify[.]com/detox56. The package has no repository, no description, and contains an unrelated Instagram data dump as padding.
- analyzed by
- Leitwacht
- first seen
- Jul 8, 2026, 09:12 AM
- analyzed
- Jul 8, 2026, 09:12 AM
Related advisories
- @devxprotect/plugin-devxprotect-experience@22.2.1
- @devxdiscover/devhub-ui@24.1.4
- cpcz-common@22.1.1
- react-dom-v17@22.1.1
- rio-design-tokens@99.99.99
- hello244b@1.0.0
- sn-flow-client@20.5.1
- mcp-server-pg@0.2.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.