@offa/offa-uwk@999.0.0
Malicious code in @offa/offa-uwk (npm)
Analysis
The postinstall hook in index.js collects the system hostname, username, current working directory, and the full process environment variables (including NPM_TOKEN, GITHUB_TOKEN, AWS_ACCESS_KEY_ID, and other credentials) and sends them via HTTPS POST to e6b10849-38dc-4280-a8e3-72ab39cfaf65[.]webhook[.]site/collect. The preinstall hook writes a marker file to /home/OFFA/flag. The package has no repository, no documented purpose, and uses version 999.0.0 with a scoped name to exploit dependency confusion.
- analyzed by
- Leitwacht
- first seen
- Jul 20, 2026, 10:24 PM
- analyzed
- Jul 20, 2026, 10:25 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.