client-cookies-agent@99.9.7
Malicious code in client-cookies-agent (npm)
T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages
Analysis
The postinstall hook runs index.js which collects the installer's hostname, current working directory, username, and local IP address via os.hostname(), os.userInfo(), and os.networkInterfaces(). This data is serialized as JSON and POSTed to lpzlajzjfkpfeefuzxbv6n5nob7bpuh6e[.]oast[.]fun/receive-data. The C2 endpoint is an interactsh (oast[.]fun) callback domain used for exfiltration. The package has no description, no repository, and no legitimate functionality — its sole purpose is host fingerprinting and beaconing on install.
- analyzed by
- Leitwacht
- first seen
- Jul 10, 2026, 05:51 PM
- analyzed
- Jul 10, 2026, 07:13 PM
Related advisories
- @wagni_bot/pumpfun-sdk@1.2.0
- @wagni_bot/solana-sdk@1.2.0
- @playerdata-internal/playerdata-core@9999.99.20
- vps-maintenance-paperclip-adapter@0.1.1
- @public-for-cdao/providers@1.0.1
- @ravespaceio/browser-input@99.0.1
- react-copy-lite@1.0.1
- prisma-callback@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.