stargateproxyserv@28.0.0
Malicious code in stargateproxyserv (npm)
Analysis
stargateproxyserv@28.0.0 is a dependency-confusion package that exfiltrates host metadata on install. The preinstall script (node index.js) collects hostname, platform, architecture, home directory, and DNS server list, then POSTs the data as JSON to ob3btwwxlwnmigvcl2m2ugmvrmxelj98[.]oastify[.]com/hit over HTTPS.
- analyzed by
- Leitwacht
- first seen
- Jul 25, 2026, 09:21 AM
- analyzed
- Jul 25, 2026, 01:28 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.