relativity-foundation-core@6.8.2
Malicious code in relativity-foundation-core (npm)
Analysis
relativity-foundation-core@6.8.2 is a trojanized package with no functional code (empty index.js). Its preinstall hook runs an inline Node.js script that collects system and CI/CD environment metadata — hostname, username, current working directory, npm registry URL, CI platform indicators, GITHUB_REPOSITORY, JENKINS_URL, and OS platform — base64-encodes the JSON payload, and exfiltrates it via an HTTPS GET request to aiwi9di43fzbjwncfrimdvkgu701orcg[.]oastify[.]com (an interact.sh-style OAST callback service). The exfiltrated data allows the attacker to identify high-value CI/CD build environments for follow-on compromise.
- analyzed by
- Leitwacht
- first seen
- Jul 18, 2026, 06:48 PM
- analyzed
- Jul 18, 2026, 06:49 PM
Related advisories
- relativity-pdfjs-dist@5.8.2
- habingeer@2.1.6
- clover-codelab-remote-pay-cloud@99.9.9
- og-boost-br@1.0.0
- crypto-javas@2.0.8
- n8n-nodes-http-probe@1.0.0
- n8n-nodes-probe@1.0.0
- n8n-nodes-port-scanner@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.