jobber-app-template-react@1.0.1
Malicious code in jobber-app-template-react (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The preinstall hook runs index.js, which collects system information (hostname, home directory, username, DNS servers, /etc/passwd, /etc/hosts) from the installer's machine and exfiltrates it via HTTPS POST to 5tzh3l2e1cetr1chf6osh4tg57b0zqnf[.]oastify[.]com (a Burp Collaborator C2 endpoint).
- analyzed by
- Leitwacht
- first seen
- Jul 27, 2026, 09:41 AM
- analyzed
- Jul 27, 2026, 09:41 AM
Related advisories
- vscode-designer-14@14.0.1
- glia-functions-tools@0.2.1
- messenger-style@1.0.1
- dynstrg-howto@1.0.1
- @ks-radar/radar@21.0.0
- basic-vite@1.0.0
- page-navigation@1.0.1
- xo-member-components@28.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.