LWA-2026-7128 MAL-2026-11065 ↗ confirmed malware

swiper_angular@5.9999.0

Malicious code in swiper_angular (npm)

T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages

Analysis

swiper_angular@5.9999.0 is a combosquat of the real swiper_angular package at a fake high version. On npm install, the preinstall hook runs preinstall.js which collects the build host's hostname, OS username, and current working directory, then exfiltrates them to an oast[.]fun callback URL (rmknhtfmmidejheotogony3qpqrk75wdz[.]oast[.]fun/cb) over HTTPS. The package has no repository and no verifiable purpose beyond this host-fingerprinting beacon.

analyzed by
Leitwacht
first seen
Jul 25, 2026, 04:15 PM
analyzed
Jul 25, 2026, 04:16 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.