fuels-versions@1.0.0
Malicious code in fuels-versions (npm)
Analysis
The package's bin script (bin/cli.js, exposed as generate-schema-ethers) runs when invoked via npx and acts as a host-metadata beacon. It collects the local username (via whoami with a fallback to os.userInfo()), the machine hostname, and the OS platform, then POSTs them as JSON to the out-of-band callback endpoint hxxps://oobme[.]kunalsharma0553[.]workers[.]dev/r/7bq6fz3l15r9 (a Cloudflare Workers URL), also sending the package name in the X-Package-Name header and request body. The package description openly states it "POSTs package name and whoami to an OOB callback."
- analyzed by
- Leitwacht
- first seen
- Aug 31, 2026, 10:45 AM
- analyzed
- Aug 31, 2026, 10:45 AM
Related advisories
- com.db.autobahn.notification-center-electron@88.88.1
- test__123q1@2.1.3
- claude-channel-telegram@9.9.9
- claude-channel-discord@9.9.9
- grafeno-payments@1.0.0
- grafeno-webhook@1.0.0
- grafeno-billing@1.0.0
- spc_login@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.