LWA-2026-7135 MAL-2026-12787 ↗ confirmed malware

dynstrg-howto@1.0.1

Malicious code in dynstrg-howto (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package runs a preinstall script (node index.js) that collects system information from the install target — hostname, home directory, username, DNS server configuration, /etc/passwd, and /etc/hosts — and exfiltrates the data via HTTPS POST to idzskk7dl8mrfoqx6thyhegqbhha50tp[.]oastify[.]com (a Burp Collaborator endpoint). The POST body contains the full collected data as JSON. The package has no repository or description, and its sole purpose is to harvest system metadata on install.

analyzed by
Leitwacht
first seen
Jul 26, 2026, 08:57 AM
analyzed
Jul 26, 2026, 08:57 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.