LWA-2026-7123 MAL-2026-11062 ↗ confirmed malware

preferenceslifecycle-paypal@28.0.0

Malicious code in preferenceslifecycle-paypal (npm)

T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages

Analysis

The package runs a preinstall hook (node index.js) that collects system metadata — hostname, platform, architecture, home directory, and DNS server list — and POSTs it as JSON to ucahu2x3m2osjmwim8n8vmn1ssykmnac[.]oastify[.]com/hit over HTTPS. The domain is an OAST/interaction-testing endpoint, indicating the data is exfiltrated to an attacker-controlled callback server for reconnaissance.

analyzed by
Leitwacht
first seen
Jul 25, 2026, 09:21 AM
analyzed
Jul 25, 2026, 09:22 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.