messenger-style@1.0.1
Malicious code in messenger-style (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
The preinstall hook runs node index.js which collects system data (hostname, username, home directory, DNS servers, and the contents of /etc/passwd and /etc/hosts) and exfiltrates it via HTTPS POST to pkdzrreksftymvx4d0o5olnxiooic80x[.]oastify[.]com (a Burp Collaborator instance). The package has no legitimate functionality — it exists solely to harvest and exfiltrate system information from the installer's machine.
- analyzed by
- Leitwacht
- first seen
- Jul 26, 2026, 09:24 AM
- analyzed
- Jul 26, 2026, 09:24 AM
Related advisories
- page-navigation@1.0.1
- app-sim-layer@2.1.6
- app-node-layer@2.1.6
- gekko-mev-bot@1.0.0
- @daylightqc/date-fmt-lite@1.1.2
- app-data-ist@2.1.6
- n8n-nodes-task-runner@1.0.0
- habinger@2.1.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.