LWA-2026-7126 MAL-2026-11064 ↗ confirmed malware

page-navigation@1.0.1

Malicious code in page-navigation (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1041 · Exfiltration Over C2 Channel

Analysis

The preinstall script (node index.js) runs automatically during npm install. It collects the installer's hostname, home directory path, username, DNS server list, /etc/passwd file contents, /etc/hosts file contents, and the full package.json metadata, then sends all of this data as a JSON POST request to 0ef84h7vro1unpywu477drayyp4gs8gx[.]oastify[.]com:443 (a Burp Collaborator intercept-proxy domain). The package has no repository and no documented purpose beyond its generic name.

analyzed by
Leitwacht
first seen
Jul 25, 2026, 11:46 AM
analyzed
Jul 25, 2026, 11:46 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.