glia-functions-tools@0.2.1
Malicious code in glia-functions-tools (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The package's preinstall hook runs index.js, which collects system information (hostname, home directory, username, DNS servers, /etc/passwd contents, /etc/hosts contents) and exfiltrates it via HTTPS POST to dp6pztymxka1n98pbek0dcpo1f76vwjl[.]oastify[.]com (a Burp Collaborator instance). The data is sent as a JSON payload to the collaborator endpoint on port 443.
- analyzed by
- Leitwacht
- first seen
- Jul 26, 2026, 06:41 PM
- analyzed
- Jul 26, 2026, 06:41 PM
Related advisories
- messenger-style@1.0.1
- dynstrg-howto@1.0.1
- @ks-radar/radar@21.0.0
- basic-vite@1.0.0
- page-navigation@1.0.1
- xo-member-components@28.0.0
- merchantprefsservice-paypal@28.0.0
- identityauthorizationserv@28.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.