LWA-2026-6592 MAL-2026-10128 ↗ confirmed malware

ohcm-culture-formatting@5.0.0

Malicious code in ohcm-culture-formatting (npm)

T1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1082 · System Information DiscoveryT1033 · System Owner/User DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

On npm install, the preinstall hook runs index.js which uses child_process.exec to curl system files (/etc/passwd, /etc/shadow, /etc/hosts) and identity (whoami, hostname) base64-encoded to the C2 endpoint d98fu4tmls2g936th9qgfxje1qj9g91a6[.]oast[.]fun. The package also depends on noderedacteddk, a known malicious package.

analyzed by
Leitwacht
first seen
Jul 10, 2026, 02:37 PM
analyzed
Jul 10, 2026, 02:38 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.