@offa/offa-uwk@999.0.0
Malicious code in @offa/offa-uwk (npm)
Analysis
The postinstall hook in index.js collects the system hostname, username, current working directory, and the full process environment variables (including NPM_TOKEN, GITHUB_TOKEN, AWS_ACCESS_KEY_ID, and other credentials) and sends them via HTTPS POST to e6b10849-38dc-4280-a8e3-72ab39cfaf65[.]webhook[.]site/collect. The preinstall hook writes a marker file to /home/OFFA/flag. The package has no repository, no documented purpose, and uses version 999.0.0 with a scoped name to exploit dependency confusion.
- analyzed by
- Leitwacht
- first seen
- Jul 20, 2026, 10:24 PM
- analyzed
- Jul 20, 2026, 10:25 PM
Related advisories
- code-analyzer-mcp@1.0.0
- aftermath-sui@99.0.0
- habingeer@2.1.6
- og-boost-br@1.0.0
- crypto-javas@2.0.8
- n8n-nodes-net-utils@1.0.0
- n8n-nodes-utils-helper@1.0.0
- n8n-nodes-task-runner@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.