nice-utils-helper@1.0.0
Malicious code in nice-utils-helper (npm)
Analysis
The package's postinstall hook runs probe.js, which performs cloud-metadata reconnaissance. It sends HTTP GET requests to the /latest/meta-data/ endpoint of cloud metadata services (AWS 169[.]254[.]169[.]254, Aliyun 100[.]100[.]100[.]200, Tencent metadata[.]tencentyun[.]com and 169[.]254[.]0[.]23) and records each endpoint's reachability status (HTTP status code, timeout, or connection error) to local files named NCODE_META.txt and NCODE_POC_MARKER.txt written into the working directory and parent directories. This probes whether the host is a cloud instance with a reachable metadata service — a reconnaissance step that precedes cloud IAM-credential harvesting.
- analyzed by
- Leitwacht
- first seen
- Aug 6, 2026, 07:46 PM
- analyzed
- Aug 6, 2026, 07:46 PM
Related advisories
- ts-enum-helper@1.0.0
- merge-grid-stats@1.0.0
- gpt-terminal-cli@1.0.0
- dojo-rn-interview@1.0.1
- wormgpt-cli@1.0.1
- mx-www-locales-common@99.0.0
- poc-ch4rlygr@1.3.0
- move-bcs-codec@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.