osinthell@1.9.5
Malicious code in osinthell (npm)
Analysis
osinthell@1.9.5 is a destructive wiper targeting Windows systems. The package exports a `sorgu()` function that triggers 26 modules performing: MBR wipe (writes zeros to \\.\PhysicalDrive0), deletion of C:\ and System32 files, termination of critical processes (explorer.exe, dwm.exe, csrss.exe, winlogon.exe), fork bombs spawning hundreds of detached cmd/powershell/node processes, memory exhaustion via large buffer allocations, disk fill with 100MB files, deletion of boot files (boot.ini, bootmgr), deletion of SAM and SECURITY registry hives, corruption of the hosts file to block google[.]com/discord[.]com/github[.]com/youtube[.]com/reddit[.]com/microsoft[.]com/windows[.]com, disabling boot recovery via bcdedit, formatting C:, truncating all files on C:\ through F:\, deleting Program Files and Users directories, overwriting pagefile.sys and hiberfil.sys, spawning infinite ping loops, and forced system shutdown. Also includes full-screen image defacement via PowerShell/mshta/Internet Explorer/VBScript using a bundled image file. No lifecycle hooks — the payload runs only when the exported function is called.
- analyzed by
- Leitwacht
- first seen
- Jul 29, 2026, 10:17 PM
- analyzed
- Jul 29, 2026, 10:18 PM
Related advisories
- super-test-json@1.2.0
- stellarfixer@1.0.0
- delta-time-32bb@1.0.0
- wormgpt-cli@1.0.1
- @offa-uwk/offa-uwk@999.0.6
- vue-plugin-bomb@1.0.1
- vite-plugin-bomb-extend@2.0.0
- vite-plugin-bomb@2.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.