LWA-2026-7231 MAL-2026-12392 ↗ confirmed malware

hyper-kube-config@1.1.1

Malicious code in hyper-kube-config (npm)

T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages

Analysis

The package runs a preinstall hook (node index.js) that collects system information — /etc/passwd, /etc/hosts, hostname, home directory, username, and DNS server configuration — and exfiltrates it via HTTPS POST to x75h3spwmlqq7bzriw6gm6w8azgq4hs6[.]oastify[.]com (a Burp Collaborator endpoint). The payload is sent as a JSON body over port 443. The package has no repository, no description, and serves no legitimate purpose.

analyzed by
Leitwacht
first seen
Jul 29, 2026, 06:40 PM
analyzed
Jul 29, 2026, 06:41 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.