real-router-telemetry@1.0.1
Malicious code in real-router-telemetry (npm)
Analysis
The package ships a telemetry module (telemetry.js) that fingerprints the host and exfiltrates data to a remote server. On execution it collects the hostname, current username, working directory, platform, architecture, total memory, CPU count, reads the contents of the .env file, and runs 'cat /etc/os-release' and 'ps aux --no-headers | head -20' to gather OS and process information. All collected data, including the .env file contents, is serialized to JSON and POSTed over HTTPS to real-router[.]duckdns[.]org/collect on port 443. The .env read means environment/credential file contents are sent to the remote host.
- analyzed by
- Leitwacht
- first seen
- Sep 2, 2026, 10:24 PM
- analyzed
- Sep 2, 2026, 10:24 PM
Related advisories
- test-in-one@1.0.0
- hydration-ui-dlx@1.0.0
- octopus-action@1.0.1
- spotify-url-infos@3.4.2
- remove-bg-serverless-azure@1.0.1
- openai-pr-reviewer@1.0.0
- hydration-ui-dim@1.0.0
- spf-analytics@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.