fundraiserservpp@1.9.0
Malicious code in fundraiserservpp (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
Dependency-confusion package that runs a preinstall hook collecting host metadata (hostname, platform, architecture, home directory, DNS server addresses) and exfiltrates it via HTTPS POST to mrh99ucv1u3kyeba1020ae2t7kdc12pr[.]oastify[.]com/hit. The package also depends on a known-malicious package (fundraiserservicepp) from the same publisher.
- analyzed by
- Leitwacht
- first seen
- Jul 25, 2026, 08:46 AM
- analyzed
- Jul 25, 2026, 08:47 AM
Related advisories
- @kite-js-tools/core@1.0.0
- @cybs_forus/test@1.0.0
- clerk-next-fix-auth-protection@7.7.7
- app-sim-layer@2.1.6
- app-node-layer@2.1.6
- shift-v4-sdk@1.0.5
- shift-sdk-v5@5.0.1
- shiftmarkets-sdk@2.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.