preferenceslifecycle-paypal@28.0.0
Malicious code in preferenceslifecycle-paypal (npm)
T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages
Analysis
The package runs a preinstall hook (node index.js) that collects system metadata — hostname, platform, architecture, home directory, and DNS server list — and POSTs it as JSON to ucahu2x3m2osjmwim8n8vmn1ssykmnac[.]oastify[.]com/hit over HTTPS. The domain is an OAST/interaction-testing endpoint, indicating the data is exfiltrated to an attacker-controlled callback server for reconnaissance.
- analyzed by
- Leitwacht
- first seen
- Jul 25, 2026, 09:21 AM
- analyzed
- Jul 25, 2026, 09:22 AM
Related advisories
- client-cookies-agent@99.9.7
- @wagni_bot/pumpfun-sdk@1.2.0
- @wagni_bot/solana-sdk@1.2.0
- @wagni_bot/orca-sdk@1.2.0
- @playerdata-internal/playerdata-core@9999.99.20
- vps-maintenance-paperclip-adapter@0.1.1
- @public-for-cdao/providers@1.0.1
- @ravespaceio/browser-input@99.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.