LWA-2026-7050 MAL-2026-12482 ↗ confirmed malware

tool-registry-scripts@1.0.0

Malicious code in tool-registry-scripts (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package's preinstall hook (node index.js) collects system information — hostname, home directory, username, DNS server list, /etc/passwd contents, and /etc/hosts contents — and POSTs the data as JSON over HTTPS to lsh5x8dwumsekllw37kacgaqxh3cr2fr[.]oastify[.]com (a Burp Collaborator / OAST exfiltration endpoint). The exfiltration was confirmed at runtime: the install process resolved the domain, connected on port 443, and transmitted the full payload including the /etc/passwd file.

analyzed by
Leitwacht
first seen
Jul 22, 2026, 08:08 PM
analyzed
Jul 22, 2026, 08:08 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.