@tuluax/errb@3.0.1
Malicious code in @tuluax/errb (npm)
Analysis
@tuluax/errb@3.0.1 is a trojanized clone of the legitimate `errno` package with a malicious install hook. The install script spawns a detached background `node index.js` process. That script AES-256-CBC-decrypts an embedded ciphertext to recover a remote URL, fetches it, and executes the returned body via eval() — a remote-code-execution dropper. At install time the process connects to backendapi-ddeaetc6gnfubvbf[.]a02[.]azurefd[.]net:443 and requests /api/health.php, receiving the payload to execute. The C2 host is backendapi-ddeaetc6gnfubvbf[.]a02[.]azurefd[.]net (Azure Front Door).
- analyzed by
- Leitwacht
- first seen
- Aug 4, 2026, 05:58 PM
- analyzed
- Aug 4, 2026, 05:58 PM
Related advisories
- webdev-conf@5.0.0
- tailwind-anime@1.1.0
- bigops-auth-interceptor@35.7.2
- bigops-header-tabs@35.8.2
- bigops-auth-provider-interceptor@35.8.3
- bigops-external-auth@35.1.6
- bigops-info-notices@35.9.8
- bigops-chat-files-hub-client@35.4.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.