LWA-2026-7113 MAL-2026-12319 ↗ confirmed malware

@kite-js-tools/core@1.0.0

Malicious code in @kite-js-tools/core (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

@kite-js-tools/core@1.0.0 is a host-reconnaissance beacon. The package contains no functional code (a 21-byte index.js). On install, the preinstall hook sends an HTTPS GET to d9hugcagp7gsdcl9dvs0frxfmqc1o8u86.oast.pro with the installer's hostname and process PID in the URL path. The postinstall hook performs a DNS resolution to a subdomain of the same oast.pro domain, also containing the hostname. oast.pro is an interact.sh callback service used to collect exfiltrated data. The package's sole purpose is to identify and report the hostnames of systems where it is installed.

analyzed by
Leitwacht
first seen
Jul 24, 2026, 11:40 PM
analyzed
Jul 24, 2026, 11:41 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.