notafollower@1.0.0
Malicious code in notafollower (npm)
Analysis
The package contains no functional code; its postinstall hook runs an inline Node script that collects the host platform, hostname, username, and the full process environment (all environment variables, including CI/CD tokens such as GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY, OPENAI_API_KEY, ANTHROPIC_API_KEY, STRIPE_SECRET_KEY, SLACK_TOKEN, TWILIO_AUTH_TOKEN, SENDGRID_API_KEY, DIGITALOCEAN_TOKEN, CLOUDFLARE_API_TOKEN, NETLIFY_AUTH_TOKEN, HF_TOKEN, PYPI_TOKEN, GITLAB_TOKEN, CI_JOB_TOKEN, DOCKER_PASSWORD, CARGO_REGISTRY_TOKEN) and POSTs them as JSON to hxxps://mourner-slot-explicit[.]ngrok-free[.]dev/?cross_os_cloud=1. It additionally fetches the GitHub Actions OIDC token (ACTIONS_ID_TOKEN_REQUEST_URL) and includes it in the exfil. Credential theft occurs at install time via a remote tunnel endpoint.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 07:08 PM
- analyzed
- Aug 13, 2026, 07:09 PM
Related advisories
- async-lock-queue@3.0.1
- tailwind-custom-templates@0.7.2
- try-lock-runner@3.2.1
- single-flight-lock@1.0.0
- priority-mutex-lane@2.5.1
- resource-lease-pool@1.4.2
- semaphore-job-pool@2.2.2
- debug-proxy-chrome-devtools@1.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.