LWA-2026-6608 MAL-2026-10019 ↗ confirmed malware

client-cookies-agent@99.9.7

Malicious code in client-cookies-agent (npm)

T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages

Analysis

The postinstall hook runs index.js which collects the installer's hostname, current working directory, username, and local IP address via os.hostname(), os.userInfo(), and os.networkInterfaces(). This data is serialized as JSON and POSTed to lpzlajzjfkpfeefuzxbv6n5nob7bpuh6e[.]oast[.]fun/receive-data. The C2 endpoint is an interactsh (oast[.]fun) callback domain used for exfiltration. The package has no description, no repository, and no legitimate functionality — its sole purpose is host fingerprinting and beaconing on install.

analyzed by
Leitwacht
first seen
Jul 10, 2026, 05:51 PM
analyzed
Jul 10, 2026, 07:13 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.