LWA-2026-6791 MAL-2026-10654 ↗ confirmed malware

@debile/require-dir@1.9.1

Malicious code in @debile/require-dir (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

@debile/require-dir@1.9.1 is a combosquat of the legitimate require-dir package. The preinstall lifecycle hook executes `curl hxxps://xgtktsypnmotaeqmgvdmqvxn785fypaau[.]oast[.]fun` on every install, beaconing installer metadata (IP address, user-agent, timing) to an attacker-controlled oast[.]fun callback endpoint. The bundled application code is a clean copy of the real require-dir module; the malicious behaviour is confined to the install hook.

analyzed by
Leitwacht
first seen
Jul 15, 2026, 01:02 AM
analyzed
Jul 15, 2026, 01:02 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.