payoutsvettingserv-paypal@28.0.0
Malicious code in payoutsvettingserv-paypal (npm)
T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages
Analysis
The package runs a preinstall script (node index.js) that collects system metadata — hostname, platform, architecture, home directory, and DNS server configuration — and POSTs it to an external C2 endpoint (2y1pgajb8aa05uiq8g9ghu99e0ks8twi[.]oastify[.]com/hit) over HTTPS. The package name is a combosquat of a PayPal internal service name, targeting dependency confusion.
- analyzed by
- Leitwacht
- first seen
- Jul 25, 2026, 09:20 AM
- analyzed
- Jul 25, 2026, 09:21 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.