@vwfs-its/sf-sac-frontend@20.1.1
Malicious code in @vwfs-its/sf-sac-frontend (npm)
Analysis
Combosquat package impersonating an internal-scoped name. On npm install, the preinstall hook (node index.js) executes a system-reconnaissance script that collects hostname, current username, user ID, group ID, shell, working directory, platform, architecture, OS type, OS release, and CPU count, then POSTs this data as JSON to hxxps://rsnchacyin4dnjv0oc8prrwn1e77vzjo[.]oastify[.]com/detox56 (an interactsh/oastify exfiltration endpoint). The tarball also contains a large filler file (package/i) of Instagram follower data used to inflate package size. No repository, no description, no legitimate purpose.
- analyzed by
- Leitwacht
- first seen
- Jul 8, 2026, 09:49 AM
- analyzed
- Jul 8, 2026, 09:50 AM
Related advisories
- dependency_confusions@99.9.9
- @comcastdevxplatforms/plugin-tenancyinformation@28.1.1
- @devxprotect/plugin-devxprotect-experience@22.2.1
- @devxdiscover/devhub-ui@24.1.4
- cpcz-common@22.1.1
- react-dom-v17@22.1.1
- rio-design-tokens@99.99.99
- hello244b@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.