pp-react-worldready-v5@1.0.0
Malicious code in pp-react-worldready-v5 (npm)
Analysis
The packages pp-react-worldready and pp-react-worldready-v5 are typosquat malware that exfiltrate CI/CD environment metadata at install time. The preinstall hook (vishu.js) performs external IP lookup via api[.]ipify[.]org, sends DNS beacons to an oastify[.]com subdomain for CI/CD fingerprinting, and exfiltrates environment variables (ci, gh_act, gh_wf) to webhook[.]site via HTTPS. The payload reads hostname, platform, and CI/CD environment variables, then beacons the data to the C2 at webhook[.]site/1b840cbf-f1a4-4d79-bf11-f1ef62949110 and via DNS to ping-build-*.your-collab-domain[.]oastify[.]com.
- analyzed by
- Leitwacht
- first seen
- Aug 1, 2026, 02:08 PM
- analyzed
- Aug 1, 2026, 04:04 PM
Related advisories
- beaver-ui-date-range-picker@12.5.3
- beaver-ui-form-object@12.1.7
- beaver-ui-form@12.6.1
- akamaijs@1.0.1
- tailwind-opentype@1.2.3
- streak-metrics-core@1.0.0
- supersig@1.0.5
- akamai-sensorv2@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.