mx-www-locales-common@99.0.0
Malicious code in mx-www-locales-common (npm)
Analysis
The postinstall hook runs a host-fingerprinting beacon. It collects the machine hostname, OS/platform/arch, CPU count, username, home directory, working directory, local IPv4 addresses, public IP (queried from ifconfig[.]me / api[.]ipify[.]org), and a broad set of CI and environment variables (GITHUB_*, GITLAB_CI, AWS_EXECUTION_ENV, npm_config_registry, HOME, PWD, USER, LOGNAME, and others), then exfiltrates the assembled JSON to hxxps://webhook[.]site/e97b40db-c35f-4f98-a2d4-3f94ad5fd668 and to a canarytokens URL (hxxp://canarytokens[.]com/images/traffic/1dgvcz6mx2ec0lb7jda73aujc/post[.]jsp) with hostname/IP/CI-vars/timestamp query parameters. It also writes the fingerprint to /tmp/mexc-confirmation-dios.txt. The package is a single-version 99.0.0 release masquerading as a MEXC internationalization-locales package.
- analyzed by
- Leitwacht
- first seen
- Aug 6, 2026, 06:43 PM
- analyzed
- Aug 6, 2026, 06:43 PM
Related advisories
- poc-ch4rlygr@1.3.0
- move-bcs-codec@1.0.0
- streak-map-cache@1.0.0
- @united-airlines-org/atmos-design-system@40.0.0
- tailwindcss-hide-scrollbar@2.5.4
- syft-acp-core@1.0.0
- syft-acp-atoms@1.0.0
- streak-cache-map@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.