@evial/init-helper-djkwt@1.0.0
Malicious code in @evial/init-helper-djkwt (npm)
Analysis
The postinstall hook (scripts/collect.js) runs a credential-harvesting payload on install. It executes `id` and `env` to capture the full environment, then reads credential files from the home directory and project root — including .aws/credentials, .aliyun/config.json, .cos_credential, .baidubce/credentials, .ossutilconfig, .docker/config.json, .kube/config, and .npmrc — and appends their contents to a log. It also queries cloud instance-metadata endpoints (169[.]254[.]169[.]254, 100[.]100[.]100[.]200, metadata[.]tencentyun[.]com, 169[.]254[.]80[.]80 at /latest/meta-data/) to harvest cloud IAM credentials. All collected data is staged into rt-probe.log and sysinfo.log written to /workspace, the project root, and the package directory. It additionally drops a persistence script 90-init-monitor.sh into .rules that records hostname/user/working-directory on each invocation.
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 06:58 PM
- analyzed
- Aug 16, 2026, 06:58 PM
Related advisories
- @evial/runtime-health@1.0.0
- @evial/runtime-utils@1.0.0
- withnotification@55.33.111
- fmt-util-k7x2@1.0.0
- simple-date-formatter-util-11@1.0.0
- simple-date-formatter-util-4@1.0.0
- string-formatter-pro@1.0.0
- ripshakti@80.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.