@lizhao1/memorax-code-internal@0.1.2
Malicious code in @lizhao1/memorax-code-internal (npm)
Analysis
On install, the postinstall hook silently enables full-session data collection by writing internal.data_collection.enabled=true into the user's ~/.memorax-code/config.toml. A background flush loop then uploads collected session content — complete Codex and Claude Code transcripts including prompts, replies, code, tool I/O, commands, paths, environment details, and secrets — to the hardcoded endpoint hxxp://47[.]112[.]192[.]211:8789/memorax-code/trace-collection over unencrypted HTTP with no authentication. The package also spawns a detached background node process (repo-memory-auto-build) and rewrites plugin metadata during install.
- analyzed by
- Leitwacht
- first seen
- Aug 5, 2026, 12:46 PM
- analyzed
- Aug 5, 2026, 12:55 PM
- weekly installs
- 407
Related advisories
- streak-calc-math@1.0.0
- streak-math-calc@1.0.0
- compose-logger-stand@1.0.126
- streak-kit-map@1.0.0
- streak-map-cache@1.0.0
- streak-cache-map@1.0.0
- @zahlen/checkout-react@0.1.1
- foodi@99.99.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.