triage_bot_using_sdkv3@2.0.1
Malicious code in triage_bot_using_sdkv3 (npm)
T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages
Analysis
The package runs a preinstall hook (node index.js) that collects system information from the installation environment — hostname, home directory, username, DNS server addresses, the contents of /etc/passwd, and the contents of /etc/hosts — and exfiltrates it via HTTPS POST to mh7rhchf58lgymyr9wffhwfprgx7lx9m[.]oastify[.]com (a Burp Collaborator / OAST callback host). The data is sent as a JSON payload to port 443 on that host.
- analyzed by
- Leitwacht
- first seen
- Jul 19, 2026, 01:02 PM
- analyzed
- Jul 19, 2026, 01:03 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.