page-navigation@1.0.1
Malicious code in page-navigation (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1041 · Exfiltration Over C2 Channel
Analysis
The preinstall script (node index.js) runs automatically during npm install. It collects the installer's hostname, home directory path, username, DNS server list, /etc/passwd file contents, /etc/hosts file contents, and the full package.json metadata, then sends all of this data as a JSON POST request to 0ef84h7vro1unpywu477drayyp4gs8gx[.]oastify[.]com:443 (a Burp Collaborator intercept-proxy domain). The package has no repository and no documented purpose beyond its generic name.
- analyzed by
- Leitwacht
- first seen
- Jul 25, 2026, 11:46 AM
- analyzed
- Jul 25, 2026, 11:46 AM
Related advisories
- app-sim-layer@2.1.6
- app-node-layer@2.1.6
- gekko-mev-bot@1.0.0
- @daylightqc/date-fmt-lite@1.1.2
- app-data-ist@2.1.6
- n8n-nodes-task-runner@1.0.0
- habinger@2.1.6
- node-as-api@2.1.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.