ohcm-culture-formatting@5.0.0
Malicious code in ohcm-culture-formatting (npm)
T1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1082 · System Information DiscoveryT1033 · System Owner/User DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
On npm install, the preinstall hook runs index.js which uses child_process.exec to curl system files (/etc/passwd, /etc/shadow, /etc/hosts) and identity (whoami, hostname) base64-encoded to the C2 endpoint d98fu4tmls2g936th9qgfxje1qj9g91a6[.]oast[.]fun. The package also depends on noderedacteddk, a known malicious package.
- analyzed by
- Leitwacht
- first seen
- Jul 10, 2026, 02:37 PM
- analyzed
- Jul 10, 2026, 02:38 PM
Related advisories
- llm-traces-app@1.0.1
- starship-timeline@1.0.1
- cardano-addresses-docs@1.0.1
- streak-metrics-math@1.0.1
- streak-metrics-core@1.0.0
- shift-v4-sdk@1.0.5
- shift-sdk-v5@5.0.1
- theta-sdk-js@1.2.14
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.