LWA-2026-6850 MAL-2026-10748 ↗ confirmed malware

string-formatter-pro@1.0.0

Malicious code in string-formatter-pro (npm)

T1059.007 · JavaScriptT1059.004 · Unix ShellT1082 · System Information DiscoveryT1552.005 · Cloud Instance Metadata APIT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The package's postinstall.js hook runs a shell command that uses curl to scrape cloud instance metadata endpoints (AWS 169[.]254[.]169[.]254, Alibaba Cloud 100[.]100[.]100[.]200 and 169[.]254[.]0[.]23, Tencent Cloud metadata[.]tencentyun[.]com) for IAM credentials, then POSTs the collected data to pwpzhsrbtvmfqrqr7onqcwnrcii960up[.]oastify[.]com via /metadata and /data paths. It also attempts to list /data/ and exfiltrate its contents to the same callback host.

analyzed by
Leitwacht
first seen
Jul 16, 2026, 01:18 PM
analyzed
Jul 16, 2026, 01:18 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.