LWA-2026-6458 MAL-2026-6972 ↗ confirmed malware

@vwfs-its/sf-sac-frontend@20.1.1

Malicious code in @vwfs-its/sf-sac-frontend (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

Combosquat package impersonating an internal-scoped name. On npm install, the preinstall hook (node index.js) executes a system-reconnaissance script that collects hostname, current username, user ID, group ID, shell, working directory, platform, architecture, OS type, OS release, and CPU count, then POSTs this data as JSON to hxxps://rsnchacyin4dnjv0oc8prrwn1e77vzjo[.]oastify[.]com/detox56 (an interactsh/oastify exfiltration endpoint). The tarball also contains a large filler file (package/i) of Instagram follower data used to inflate package size. No repository, no description, no legitimate purpose.

analyzed by
Leitwacht
first seen
Jul 8, 2026, 09:49 AM
analyzed
Jul 8, 2026, 09:50 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.