LWA-2026-6574 MAL-2026-10095 ↗ confirmed malware

fury_frontend-andes-ui@99.9.5

Malicious code in fury_frontend-andes-ui (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The postinstall hook (node index.js) executes index.js which collects the installer's username, current working directory, external IP address, and the package name, then POSTs this data as JSON to dodwqvexnkotaavogofbj9kjz5pltcu7b[.]oast[.]fun:80/receive-data. This is a host-reconnaissance beacon that exfiltrates system metadata on install.

analyzed by
Leitwacht
first seen
Jul 9, 2026, 08:01 PM
analyzed
Jul 9, 2026, 08:01 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.