fundraiserserv@28.0.0
Malicious code in fundraiserserv (npm)
Analysis
fundraiserserv@28.0.0 is a dependency-confusion package that exfiltrates host metadata on install. The preinstall script (node index.js) collects hostname, platform, architecture, home directory, and DNS server list, then POSTs the data as JSON to gyi3gojp8oae58i48u9uh89neek681wq[.]oastify[.]com/hit over HTTPS.
- analyzed by
- Leitwacht
- first seen
- Jul 25, 2026, 09:38 AM
- analyzed
- Jul 25, 2026, 01:28 PM
Related advisories
- relativity-pdfjs-dist@99.9.9
- client-cookies-agent@99.9.7
- @wagni_bot/pumpfun-sdk@1.2.0
- @wagni_bot/solana-sdk@1.2.0
- @playerdata-internal/playerdata-core@9999.99.20
- vps-maintenance-paperclip-adapter@0.1.1
- @public-for-cdao/providers@1.0.1
- @ravespaceio/browser-input@99.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.