LWA-2026-7175 MAL-2026-12360 ↗ confirmed malware

csv-parser-helper@1.0.0

Malicious code in csv-parser-helper (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package csv-parser-helper@1.0.0 is a combosquat of common CSV parsing utility names. Its postinstall hook executes postinstall.js, which collects extensive system and CI/CD environment metadata — hostname, username, working directory, OS details, container/docker detection, process tree, GitHub CI variables (GITHUB_REPOSITORY, GITHUB_ACTOR, GITHUB_RUN_ID, CI, RUNNER_NAME), IP addresses, DNS configuration, cloud metadata probes (Tencent Cloud and AWS metadata endpoints), and the full environment — then base64-encodes the collected data and exfiltrates it via an HTTP GET request to the OAST callback domain pzs5w7ntzhsnepwk564lyfdci3oucl0a[.]oastify[.]com at path /z with the encoded data as the d parameter.

analyzed by
Leitwacht
first seen
Jul 28, 2026, 08:06 AM
analyzed
Jul 28, 2026, 08:07 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.