identityauthorizationserv@28.0.0
Malicious code in identityauthorizationserv (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
Package identityauthorizationserv@28.0.0 is a dependency-confusion package that exfiltrates host metadata on install. The preinstall hook runs index.js, which collects hostname, platform, architecture, home directory, and DNS server list, then POSTs this data as JSON to lwl8ethu6t8j3dg96z7zfd7scjib68ux[.]oastify[.]com/hit over HTTPS. The package description is "Dependency confusion proof of concept package".
- analyzed by
- Leitwacht
- first seen
- Jul 25, 2026, 09:20 AM
- analyzed
- Jul 25, 2026, 09:22 AM
Related advisories
- fundraiserservpp@1.9.0
- @kite-js-tools/core@1.0.0
- @cybs_forus/test@1.0.0
- clerk-next-fix-auth-protection@7.7.7
- app-sim-layer@2.1.6
- app-node-layer@2.1.6
- shift-v4-sdk@1.0.5
- shift-sdk-v5@5.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.