fundraiserservicepp@1.7.0
Malicious code in fundraiserservicepp (npm)
T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages
Analysis
fundraiserservicepp@1.7.0 is a dependency-confusion package that exfiltrates host metadata on install. The preinstall script (node index.js) collects hostname, platform, and architecture, then POSTs the data as JSON to rpke7za0zz1pwj9fz5058j0y5pbgz82wr[.]oastify[.]com/hit over HTTPS.
- analyzed by
- Leitwacht
- first seen
- Jul 25, 2026, 08:21 AM
- analyzed
- Jul 25, 2026, 01:28 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.