Cremit
/incidentsfield log
CatchesCampaignsExfilPatternsLLMIncidentsMethodology
↺rss↗cremit.io

incidents.cremit.io

A reference feed of real-world Non-Human Identity (NHI) credential leak incidents. Maintained by Cremit.

Browse

  • All incidents
  • npm supply chain
  • CI/CD compromise
  • Methodology

Subscribe

  • RSS feed
  • @cremit_io
  • GitHub
// status
monitor active
// build
2026-06-15
// origin
cremit · seoul, kr
// license
CC BY 4.0

© 2026 Cremit. content reuse encouraged with attribution.

home/campaigns/npm/dewifewi

// publisher campaign · npm

dewifewi

All caught packages published by the dewifewi account on npm, plus the author + maintainer info the registry currently exposes. Use this view to pivot: shared emails / names across packages are strong evidence of a single attacker behind multiple throwaway handles.

↗npmjs.com publisher↗pypi.org user
packages
5
distinct names
catch events
12
versions × names
blast
—
combined weekly downloads
active span
2026-05-19 → 2026-05-20
first → last catch

// publisher osint

Account-level signals. Activity span tells you how long this handle has been around (fresh = throwaway-prone). Email domains separate single-use webmail from real org addresses. Cross-ecosystem handles + GitHub links are the strongest attribution pivot — same name on multiple registries usually means same operator.

activity on npm

Not available on this ecosystem (registry search unsupported).

same handle on other registries
  • npm /~dewifewi: not found
  • pypi /user/dewifewi: exists ↗
  • github.com/dewifewi: not found

// exfil path

what is read → where it ships
steals
  • ○ home dir
  • ○ system info
→
sends to
  • ⇢ lszakfghwnvxspyfcmaabd1css99rnq3w.oast.fun(oast.fun)
  • ⚙ dns tunneling(fetches + executes remote payload)

Targets resolved from static-analysis flags; destinations extracted from the captured code excerpt. Full list + structured fields available in the IOC panel below.

// shared exfil infrastructure

Webhook URLs and public IPs referenced by more than one package in this campaign — the smoking-gun signal for shared backend infrastructure.

shared webhook URLs (1)
  • lszakfghwnvxspyfcmaabd1css99rnq3w.oast.fun(5 pkgs: claude-internal-utils, anthropic-shared-logger, private-next-pages, did-0091, stripe-internal-utils)

// pattern footprint

Static-analysis flags that fired across the campaign, with how many packages each touched. Use as the "what kind of stealer is this" answer.

  • ×5
  • ×5
  • ×5
  • ×5
  • ×5
  • ×5

// packages in this campaign

5 distinct · newest first
reads-env-vars
reads-homedir
reads-system-info
dns-tunneling
child-process-spawn
dest-via-hostname-var
AUTO-PUBLISHED/npm/2026-05-20

claude-internal-utils@9.0.5

by dewifewi

Alex Birsan Style

→ sends tolszakfghwnvxspyfcmaabd1css99rnq3w.oast.fun
reads-env-varsreads-homedirreads-system-infodns-tunnelingchild-process-spawndest-via-hostname-var

→ Sends to suspicious destination(s): lszakfghwnvxspyfcmaabd1css99rnq3w.oast.fun.

weekly
—
/wk
llm verdict
malicious 0.95
h-score
99
patterns
6
size
1.0 KB
versions
1
AUTO-PUBLISHED/npm/2026-05-20

anthropic-shared-logger@8.0.5

by dewifewi

Full RCE PoC - Alex Birsan Style

→ sends tolszakfghwnvxspyfcmaabd1css99rnq3w.oast.fun
reads-env-varsreads-homedirreads-system-infodns-tunnelingchild-process-spawndest-via-hostname-var

→ Sends to suspicious destination(s): lszakfghwnvxspyfcmaabd1css99rnq3w.oast.fun.

weekly
—
/wk
llm verdict
malicious 0.95
h-score
100
patterns
6
size
1.0 KB
versions
1
AUTO-PUBLISHED/npm/2026-05-20

private-next-pages@9.0.5

by dewifewi

Style

→ sends tolszakfghwnvxspyfcmaabd1css99rnq3w.oast.fun
reads-env-varsreads-homedirreads-system-infodns-tunnelingchild-process-spawndest-via-hostname-var

→ Sends to suspicious destination(s): lszakfghwnvxspyfcmaabd1css99rnq3w.oast.fun.

weekly
—
/wk
llm verdict
malicious 0.95
h-score
87
patterns
6
size
1008 B
versions
1
AUTO-PUBLISHED/npm/2026-05-20

did-00917 versions·11.0.5→11.2.8

by dewifewi

xxx

→ sends tolszakfghwnvxspyfcmaabd1css99rnq3w.oast.fun
reads-env-varsreads-homedirreads-system-infodns-tunnelingchild-process-spawndest-via-hostname-var

→ Sends to suspicious destination(s): lszakfghwnvxspyfcmaabd1css99rnq3w.oast.fun.

weekly
—
/wk
llm verdict
malicious 0.95
h-score
67
patterns
6
size
977 B
versions
8
AUTO-PUBLISHED/npm/2026-05-20

stripe-internal-utils2 versions·1.0.0→8.2.0

by dewifewi

Full RCE PoC -osama

→ sends tolszakfghwnvxspyfcmaabd1css99rnq3w.oast.fun
reads-env-varsreads-homedirreads-system-infodns-tunnelingchild-process-spawndest-via-hostname-var

→ Sends to suspicious destination(s): lszakfghwnvxspyfcmaabd1css99rnq3w.oast.fun.

weekly
—
/wk
llm verdict
malicious 0.95
h-score
85
patterns
6
size
1.0 KB
versions
2