LWA-2026-6942 MAL-2026-10778 ↗ confirmed malware

relativity-pdfjs-dist@99.9.9

Malicious code in relativity-pdfjs-dist (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

relativity-pdfjs-dist@99.9.9 is a combosquat of the legitimate pdfjs-dist package. The preinstall hook runs an inline script that collects hostname, username, current working directory, npm registry URL, CI/CD environment variables (CI, GITHUB_REPOSITORY, JENKINS_URL), and platform information, then exfiltrates this data via an HTTPS GET request to 9u4hlcu3febavvzbrqulpuwf66cy0qof[.]oastify[.]com. The package contains only a package.json and an empty index.js stub — no actual PDF.js functionality.

analyzed by
Leitwacht
first seen
Jul 18, 2026, 08:59 AM
analyzed
Jul 18, 2026, 01:26 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.