Hostile 100% javascript Download

otomi-console 9.9.9

preinstall exfiltrates system data

npm install hook POSTs public IP to a literal IPv4 endpointJavaScript discovers public IP and POSTs to a literal IPv4 endpoint
SHA-256a285d0feea697809e11a73e940fad166d6da4559f7dadd33739155c9dd8bdef1

Also flagged by osv (MAL-2026-2788: Malicious code in otomi-console (npm)) +2 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.