@fedfub/string-utils@1.0.0
Malicious code in @fedfub/string-utils (npm)
Analysis
The postinstall hook executes a bundled script that acts as a self-propagating implant. On install it harvests environment variables matching KEY/SECRET/TOKEN/PASS/AWS/JWT/STRIPE/PAYPAL/DB_/DATABASE/REDIS/MONGO, recursively reads source files (.js, .ts, .py, .go, .rs, .java, .c, .cpp, .h, .cs, .rb, .php) from the working directory, and reads SSH keys from ~/.ssh, then POSTs all collected data to 73[.]218[.]105[.]44:8080/collect. It self-propagates by publishing a <dependency>-patch package (version 99.0.0) containing the same payload for every dependency of the current project, and injects a dependency into package.json files across the home directory. It installs persistence via a scheduled task (Windows) or a @reboot cron entry (Linux). It beacons every 30 seconds to 73[.]218[.]105[.]44:8080/cmd?id=<id> and executes returned commands, posting command output to /result.
- analyzed by
- Leitwacht
- first seen
- Aug 7, 2026, 08:39 AM
- analyzed
- Aug 7, 2026, 08:40 AM
Related advisories
- weight2loss@1.0.5
- gpt-terminal-cli@1.0.0
- streak-metrics-core@1.0.0
- system-performance-helper@1.0.1
- solana-key-utils@1.0.0
- eth-wallet-helpers@1.0.0
- crypto-validate-lib@1.0.0
- layer2-sdk@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.