hyper-kube-config@1.1.1
Malicious code in hyper-kube-config (npm)
T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages
Analysis
The package runs a preinstall hook (node index.js) that collects system information — /etc/passwd, /etc/hosts, hostname, home directory, username, and DNS server configuration — and exfiltrates it via HTTPS POST to x75h3spwmlqq7bzriw6gm6w8azgq4hs6[.]oastify[.]com (a Burp Collaborator endpoint). The payload is sent as a JSON body over port 443. The package has no repository, no description, and serves no legitimate purpose.
- analyzed by
- Leitwacht
- first seen
- Jul 29, 2026, 06:40 PM
- analyzed
- Jul 29, 2026, 06:41 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.