swiper_angular@5.9999.0
Malicious code in swiper_angular (npm)
T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages
Analysis
swiper_angular@5.9999.0 is a combosquat of the real swiper_angular package at a fake high version. On npm install, the preinstall hook runs preinstall.js which collects the build host's hostname, OS username, and current working directory, then exfiltrates them to an oast[.]fun callback URL (rmknhtfmmidejheotogony3qpqrk75wdz[.]oast[.]fun/cb) over HTTPS. The package has no repository and no verifiable purpose beyond this host-fingerprinting beacon.
- analyzed by
- Leitwacht
- first seen
- Jul 25, 2026, 04:15 PM
- analyzed
- Jul 25, 2026, 04:16 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.