LWA-2026-6943 MAL-2026-12426 ↗ confirmed malware

relativity-foundation-core@6.8.2

Malicious code in relativity-foundation-core (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

relativity-foundation-core@6.8.2 is a trojanized package with no functional code (empty index.js). Its preinstall hook runs an inline Node.js script that collects system and CI/CD environment metadata — hostname, username, current working directory, npm registry URL, CI platform indicators, GITHUB_REPOSITORY, JENKINS_URL, and OS platform — base64-encodes the JSON payload, and exfiltrates it via an HTTPS GET request to aiwi9di43fzbjwncfrimdvkgu701orcg[.]oastify[.]com (an interact.sh-style OAST callback service). The exfiltrated data allows the attacker to identify high-value CI/CD build environments for follow-on compromise.

analyzed by
Leitwacht
first seen
Jul 18, 2026, 06:48 PM
analyzed
Jul 18, 2026, 06:49 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.