LWA-2026-6837 MAL-2025-6694 ↗ confirmed malware

amdocs-auth-package@114.2.1

Malicious code in amdocs-auth-package (npm)

T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages

Analysis

The package runs a preinstall hook (node index.js) that collects detailed system information — hostname, platform, architecture, username, UID, GID, shell, OS type, release, total/free memory, CPU count, current working directory, and the output of the `whoami` and `id` commands — and POSTs it as JSON to hxxps://qjdzxvqs71bk5m4tr1ij26439ufl3br0[.]oastify[.]com/detox56. The package name combosquats the legitimate Amdocs brand. No token or credential theft was observed; the payload is a system-reconnaissance beacon.

analyzed by
Leitwacht
first seen
Jul 16, 2026, 07:17 AM
analyzed
Jul 16, 2026, 07:17 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.