LWA-2026-7125 MAL-2026-5172 ↗ confirmed malware

fundraiserserv@28.0.0

Malicious code in fundraiserserv (npm)

Analysis

fundraiserserv@28.0.0 is a dependency-confusion package that exfiltrates host metadata on install. The preinstall script (node index.js) collects hostname, platform, architecture, home directory, and DNS server list, then POSTs the data as JSON to gyi3gojp8oae58i48u9uh89neek681wq[.]oastify[.]com/hit over HTTPS.

analyzed by
Leitwacht
first seen
Jul 25, 2026, 09:38 AM
analyzed
Jul 25, 2026, 01:28 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.