LWA-2026-7122 MAL-2026-11057 ↗ confirmed malware

merchantprefsservice-paypal@28.0.0

Malicious code in merchantprefsservice-paypal (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Dependency-confusion package (name mimics an internal PayPal service name) runs a preinstall hook that exfiltrates system metadata to a remote C2 server. On install, index.js collects hostname, platform, architecture, home directory, and DNS server list, then POSTs the data as JSON to fdw2vnyonnpdk7x3ntotw7omtdz5n4bt[.]oastify[.]com:443/hit over HTTPS. The package has no repository and no legitimate functionality beyond this beacon.

analyzed by
Leitwacht
first seen
Jul 25, 2026, 09:20 AM
analyzed
Jul 25, 2026, 09:22 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.