@offa-uwk/offa-uwk@999.0.6
Malicious code in @offa-uwk/offa-uwk (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1529 · System Shutdown/Reboot
Analysis
Dependency-confusion stub (scoped name @offa-uwk/offa-uwk, version 999.0.6) with a postinstall hook that runs index.js. The script collects the hostname, username, current working directory, and timestamp, then POSTs this metadata as JSON to webhook[.]site/e6b10849-38dc-4280-a8e3-72ab39cfaf65. After exfiltration, it executes shutdown -h now (or systemctl poweroff as fallback) to halt the system. A preinstall hook also writes a marker file to /home/OFFA/flag. The package has no repository, no meaningful description, and ships only a 1.5KB index.js.
- analyzed by
- Leitwacht
- first seen
- Jul 20, 2026, 10:55 PM
- analyzed
- Jul 20, 2026, 10:55 PM
Related advisories
- vue-plugin-bomb@1.0.1
- vite-plugin-bomb-extend@2.0.0
- vite-plugin-bomb@2.0.0
- osinthell@1.9.5
- twilio-internal@99.99.99
- twilio-functions@99.99.99
- relativity-foundation-core@6.8.2
- relativity-pdfjs-dist@5.8.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.