boardwalk-js-tests@1.1.1
Malicious code in boardwalk-js-tests (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The preinstall hook runs index.js, which collects system information (hostname, username, home directory, DNS servers, /etc/passwd, /etc/hosts) and exfiltrates it via HTTPS POST to h8q14cqgn5ra8v0bjg70nqxsbjhc52tr[.]oastify[.]com (a Burp Collaborator intercept endpoint).
- analyzed by
- Leitwacht
- first seen
- Aug 1, 2026, 11:41 AM
- analyzed
- Aug 1, 2026, 11:41 AM
Related advisories
- a.poltoradnev-package-c@6.1.10
- aedes_clusters@1.0.1
- sui-migration-audit-rules@1.0.0
- hardhat-hold@2.21.0
- @latlongid/location@1.0.1
- streak-metrics-math@1.0.1
- streak-math-metrics@1.0.0
- streak-metrics-core@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.