LWA-2026-7120 MAL-2026-11100 ↗ confirmed malware

identityauthorizationserv@28.0.0

Malicious code in identityauthorizationserv (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Package identityauthorizationserv@28.0.0 is a dependency-confusion package that exfiltrates host metadata on install. The preinstall hook runs index.js, which collects hostname, platform, architecture, home directory, and DNS server list, then POSTs this data as JSON to lwl8ethu6t8j3dg96z7zfd7scjib68ux[.]oastify[.]com/hit over HTTPS. The package description is "Dependency confusion proof of concept package".

analyzed by
Leitwacht
first seen
Jul 25, 2026, 09:20 AM
analyzed
Jul 25, 2026, 09:22 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.