xo-member-components@28.0.0
Malicious code in xo-member-components (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
Dependency-confusion package that exfiltrates host fingerprint data on install. The preinstall hook runs index.js which collects the hostname, platform, architecture, home directory path, and DNS server list, then POSTs this data as JSON to bq5y8jbk0j29x3az0p1p931i69c10sqgf[.]oastify[.]com/hit over HTTPS. The package has no legitimate functionality beyond this beacon.
- analyzed by
- Leitwacht
- first seen
- Jul 25, 2026, 09:20 AM
- analyzed
- Jul 25, 2026, 09:23 AM
Related advisories
- merchantprefsservice-paypal@28.0.0
- identityauthorizationserv@28.0.0
- fundraiserservpp@1.9.0
- @kite-js-tools/core@1.0.0
- @cybs_forus/test@1.0.0
- clerk-next-fix-auth-protection@7.7.7
- app-sim-layer@2.1.6
- app-node-layer@2.1.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.