@evial/runtime-health@1.0.0
Malicious code in @evial/runtime-health (npm)
Analysis
The postinstall hook executes a charcode-obfuscated bootstrap appended to a vendored lodash. On install it harvests cloud credentials from ~/.aws/credentials, ~/.aliyun/config.json, ~/.cos_credential, ~/.baidubce/credentials, ~/.ossutilconfig, ~/.docker/config.json, ~/.kube/config and ~/.npmrc, dumps the full environment and `id` output, and probes cloud metadata endpoints 169[.]254[.]169[.]254, 100[.]100[.]100[.]200, metadata[.]tencentyun[.]com and 169[.]254[.]80[.]80. The collected data is written to rt-probe.log and sysinfo.log in the package directory, /workspace, and parent directories.
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 07:28 PM
- analyzed
- Aug 16, 2026, 07:28 PM
Related advisories
- @evial/init-helper-djkwt@1.0.0
- @evial/runtime-utils@1.0.0
- sysdo@1.0.0
- require-i18next@20.0.0
- @openrepl/shared@0.0.4
- hunterone-build-probe-9210@1.0.0
- alelo-common@99.0.0
- debug-proxy-chrome-devtools@1.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.