dynstrg-howto@1.0.1
Malicious code in dynstrg-howto (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The package runs a preinstall script (node index.js) that collects system information from the install target — hostname, home directory, username, DNS server configuration, /etc/passwd, and /etc/hosts — and exfiltrates the data via HTTPS POST to idzskk7dl8mrfoqx6thyhegqbhha50tp[.]oastify[.]com (a Burp Collaborator endpoint). The POST body contains the full collected data as JSON. The package has no repository or description, and its sole purpose is to harvest system metadata on install.
- analyzed by
- Leitwacht
- first seen
- Jul 26, 2026, 08:57 AM
- analyzed
- Jul 26, 2026, 08:57 AM
Related advisories
- @ks-radar/radar@21.0.0
- basic-vite@1.0.0
- page-navigation@1.0.1
- xo-member-components@28.0.0
- merchantprefsservice-paypal@28.0.0
- identityauthorizationserv@28.0.0
- fundraiserservpp@1.9.0
- @kite-js-tools/core@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.