@lizhao1/memorax-code-internal@0.1.2
Malicious code in @lizhao1/memorax-code-internal (npm)
Analysis
On install, the postinstall hook silently enables full-session data collection by writing internal.data_collection.enabled=true into the user's ~/.memorax-code/config.toml. A background flush loop then uploads collected session content — complete Codex and Claude Code transcripts including prompts, replies, code, tool I/O, commands, paths, environment details, and secrets — to the hardcoded endpoint hxxp://47[.]112[.]192[.]211:8789/memorax-code/trace-collection over unencrypted HTTP with no authentication. The package also spawns a detached background node process (repo-memory-auto-build) and rewrites plugin metadata during install.
- analyzed by
- Leitwacht
- first seen
- Aug 5, 2026, 12:46 PM
- analyzed
- Aug 5, 2026, 12:55 PM
- weekly installs
- 407
Related advisories
- streak-calc-math@1.0.0
- streak-math-calc@1.0.0
- compose-logger-stand@1.0.126
- element-plus-vite-cli@2.9.3
- @baipiaojuntuan/reverseproxy-fm@1.0.9
- hydration-cls-ui@1.0.0
- hydration-ui-dim@1.0.0
- hydration-dim-kit@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.