@kite-js-tools/core@1.0.0
Malicious code in @kite-js-tools/core (npm)
Analysis
@kite-js-tools/core@1.0.0 is a host-reconnaissance beacon. The package contains no functional code (a 21-byte index.js). On install, the preinstall hook sends an HTTPS GET to d9hugcagp7gsdcl9dvs0frxfmqc1o8u86.oast.pro with the installer's hostname and process PID in the URL path. The postinstall hook performs a DNS resolution to a subdomain of the same oast.pro domain, also containing the hostname. oast.pro is an interact.sh callback service used to collect exfiltrated data. The package's sole purpose is to identify and report the hostnames of systems where it is installed.
- analyzed by
- Leitwacht
- first seen
- Jul 24, 2026, 11:40 PM
- analyzed
- Jul 24, 2026, 11:41 PM
Related advisories
- @cybs_forus/test@1.0.0
- clerk-next-fix-auth-protection@7.7.7
- app-sim-layer@2.1.6
- app-node-layer@2.1.6
- shift-v4-sdk@1.0.5
- shift-sdk-v5@5.0.1
- shiftmarkets-sdk@2.1.0
- @cryptosrvc/shift-exchange-root@3.9.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.