LWA-2026-7124 MAL-2026-11063 ↗ confirmed malware

xo-member-components@28.0.0

Malicious code in xo-member-components (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Dependency-confusion package that exfiltrates host fingerprint data on install. The preinstall hook runs index.js which collects the hostname, platform, architecture, home directory path, and DNS server list, then POSTs this data as JSON to bq5y8jbk0j29x3az0p1p931i69c10sqgf[.]oastify[.]com/hit over HTTPS. The package has no legitimate functionality beyond this beacon.

analyzed by
Leitwacht
first seen
Jul 25, 2026, 09:20 AM
analyzed
Jul 25, 2026, 09:23 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.