LWA-2026-6944 MAL-2026-11153 ↗ confirmed malware

triage_bot_using_sdkv3@2.0.1

Malicious code in triage_bot_using_sdkv3 (npm)

T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages

Analysis

The package runs a preinstall hook (node index.js) that collects system information from the installation environment — hostname, home directory, username, DNS server addresses, the contents of /etc/passwd, and the contents of /etc/hosts — and exfiltrates it via HTTPS POST to mh7rhchf58lgymyr9wffhwfprgx7lx9m[.]oastify[.]com (a Burp Collaborator / OAST callback host). The data is sent as a JSON payload to port 443 on that host.

analyzed by
Leitwacht
first seen
Jul 19, 2026, 01:02 PM
analyzed
Jul 19, 2026, 01:03 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.