@dgn-src-click-to-pay-org/srcdcfreleasecert@999.0.1
Malicious code in @dgn-src-click-to-pay-org/srcdcfreleasecert (npm)
Analysis
The package's postinstall hook (scripts/check-env.js) runs on install and sends a covert host-metadata beacon to hxxp://16-171-38-148[.]sslip[.]io:8080/api/install (IP 16[.]171[.]38[.]148:8080). The JSON payload contains the package name/version, the installer's operating system platform, CPU architecture, and Node.js version. This network callback is undocumented and unrelated to the package's declared payment-utility purpose (amount formatting, PAN masking, Luhn validation). The endpoint can be redirected via the DGN_SRC_ENDPOINT environment variable.
- analyzed by
- Leitwacht
- first seen
- Aug 11, 2026, 05:26 PM
- analyzed
- Aug 11, 2026, 05:29 PM
Related advisories
- developer-dashboard@1.0.2
- passkeys-react@1.0.1
- @openzeppelin-5/contracts@1.0.0
- @openzeppelin-4/contracts@1.0.0
- ghazaly@99.9.0
- permit2@1.0.0
- dependencyfsdsfdsfg@99.9.0
- ethereum-vault-connector@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.