LWA-2026-7119 MAL-2026-11103 ↗ confirmed malware

stargateproxyserv@28.0.0

Malicious code in stargateproxyserv (npm)

Analysis

stargateproxyserv@28.0.0 is a dependency-confusion package that exfiltrates host metadata on install. The preinstall script (node index.js) collects hostname, platform, architecture, home directory, and DNS server list, then POSTs the data as JSON to ob3btwwxlwnmigvcl2m2ugmvrmxelj98[.]oastify[.]com/hit over HTTPS.

analyzed by
Leitwacht
first seen
Jul 25, 2026, 09:21 AM
analyzed
Jul 25, 2026, 01:28 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.