// npm package
private-next-pages
Style
versions
1
maintainers
1
first publish
2021-08-01
publisher
dewifewi
tarball
1,008 B
AUTO-PUBLISHED·1 version indexed·latest published 2026-05-20
// exfil path
what is read → where it shipssteals
- ○ home dir
- ○ system info
sends to
- ⇢ lszakfghwnvxspyfcmaabd1css99rnq3w.oast.fun(oast.fun)
- ⚙ dns tunneling(fetches + executes remote payload)
// publisher campaignby dewifewi
5 caught packages from this accountThis is not an isolated catch. The same publisher has shipped 4 other packages that our pipeline flagged — the shape of a coordinated campaign, not a one-off. Each link below opens that sibling's analysis.
// offending code· @9.0.5· 1 file flagged
llm: malicious · 0.95→ Sends to suspicious destination(s): lszakfghwnvxspyfcmaabd1css99rnq3w.oast.fun.
- @9.0.5··AUTO-PUBLISHED·publisher: dewifewiheuristic 87/100static flags 6llm malicious (0.95) via ollamainstall-scripts:postinstallnew-publisher:1dfirst-version-of-packagepublisher-multi-name-burst:2publisher-version-pump:11reads-env-varsreads-homedirreads-system-infodns-tunnelingchild-process-spawndest-via-hostname-var
→ Sends to suspicious destination(s): lszakfghwnvxspyfcmaabd1css99rnq3w.oast.fun.
// NHI intent2 targets·mixed harvest patterns·
