fury_frontend-andes-ui@99.9.5
Malicious code in fury_frontend-andes-ui (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The postinstall hook (node index.js) executes index.js which collects the installer's username, current working directory, external IP address, and the package name, then POSTs this data as JSON to dodwqvexnkotaavogofbj9kjz5pltcu7b[.]oast[.]fun:80/receive-data. This is a host-reconnaissance beacon that exfiltrates system metadata on install.
- analyzed by
- Leitwacht
- first seen
- Jul 9, 2026, 08:01 PM
- analyzed
- Jul 9, 2026, 08:01 PM
Related advisories
- cookie-phase@2.3.5
- polymarket-mcp-v2@2.1.6
- chunk-parser@1.0.0
- nonenull1@1.0.0
- es6-codify@2.2.0
- chai-as-smart@2.3.5
- @wagni_bot/meteora-sdk@1.2.0
- @wagni_bot/ethereum-wallet@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.