url
https://oob.moika.tech/report
discovered 2026-05-28
Exfiltration endpoint. Receives HTTP POST with process.env, hostname, username, platform, arch, cwd, Node.js version, and X-Secret authentication header.
Campaigns
Linked packages
- npm @cloudplatform-single-spa/billingexfiltrates-to
- npm @car-loans/mobile-car-loans-applicationexfiltrates-to
- npm @mlspace/shared-storageexfiltrates-to
- npm @fb-deposit/form-depositexfiltrates-to
- npm @debit-ib/mobile-debit-ib-additional-card-formexfiltrates-to
- npm @t-in-one/add_applicationexfiltrates-to
- npm @capibar.chat/ui-kitexfiltrates-to
- npm @sber-ecom-core/sberpay-widgetexfiltrates-to
- npm @emcd-vue/authexfiltrates-to
- npm @emcd-vue/loansexfiltrates-to
- npm @emcd-vue/b2b-pay-formexfiltrates-to
