preferenceslifecycle-paypal@28.0.0
Malicious code in preferenceslifecycle-paypal (npm)
T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages
Analysis
The package runs a preinstall hook (node index.js) that collects system metadata — hostname, platform, architecture, home directory, and DNS server list — and POSTs it as JSON to ucahu2x3m2osjmwim8n8vmn1ssykmnac[.]oastify[.]com/hit over HTTPS. The domain is an OAST/interaction-testing endpoint, indicating the data is exfiltrated to an attacker-controlled callback server for reconnaissance.
- analyzed by
- Leitwacht
- first seen
- Jul 25, 2026, 09:21 AM
- analyzed
- Jul 25, 2026, 09:22 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.