axios-fast@1.0.0
Malicious code in axios-fast (npm)
T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
The package's preinstall hook runs a node one-liner that POSTs the installer's complete environment variables (including NPM_TOKEN, GITHUB_TOKEN, and any cloud credentials) as JSON to the collector URL hxxps://webhook[.]site/31e82bcd-a220-42e6-82f0-4f082e8fa80e/ on install. The bundled source code is a benign fetch-based HTTP client; the credential exfiltration occurs entirely in the install lifecycle hook.
- analyzed by
- Leitwacht
- first seen
- Aug 14, 2026, 01:43 PM
- analyzed
- Aug 14, 2026, 01:44 PM
Related advisories
- meualelo@99.0.2
- alelo-auth@99.0.2
- alelo-api@99.0.2
- alelo-utils@99.0.0
- alelo-services@99.0.0
- alelo-common@99.0.0
- alelo-client@99.0.0
- alelo-payment@99.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.