@debile/require-dir@1.9.1
Malicious code in @debile/require-dir (npm)
T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
@debile/require-dir@1.9.1 is a combosquat of the legitimate require-dir package. The preinstall lifecycle hook executes `curl hxxps://xgtktsypnmotaeqmgvdmqvxn785fypaau[.]oast[.]fun` on every install, beaconing installer metadata (IP address, user-agent, timing) to an attacker-controlled oast[.]fun callback endpoint. The bundled application code is a clean copy of the real require-dir module; the malicious behaviour is confined to the install hook.
- analyzed by
- Leitwacht
- first seen
- Jul 15, 2026, 01:02 AM
- analyzed
- Jul 15, 2026, 01:02 AM
Related advisories
- @asyncapi/generator-helpers@1.1.1
- eth-dev@1.0.2
- @vite-js/vui@7.14.16
- awesome-terminal@1.0.3
- type-context@3.2.7
- terminal-mascot@3.5.2
- pure-folder-three@0.7.3
- tinyparrot@0.4.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.