fieldbase-webapplication-buildtools@99.99.99
Malicious code in fieldbase-webapplication-buildtools (npm)
T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
The package's preinstall and install hooks run on installation. They base64-encode the current username, hostname, working directory, and package name, then POST that data to hxxps://eoy34oyrep9j5x8[.]m[.]pipedream[.]net/<encoded-data> via curl. The hooks also perform a DNS lookup exfiltration channel by base64-encoding the package name and resolving it as a subdomain of eoy34oyrep9j5x8[.]m[.]pipedream[.]net via nslookup. The package ships an empty index.js; all behaviour is in the install lifecycle scripts.
- analyzed by
- Leitwacht
- first seen
- Sep 3, 2026, 02:15 PM
- analyzed
- Sep 3, 2026, 02:16 PM
Related advisories
- @stellarshift/chain-metadata@1.0.1
- @stellarshift/abi-tools@1.0.1
- cbc97b7a@1.1787999998.0
- grafeno-payments@1.0.0
- grafeno-billing@1.0.0
- spc_login@1.0.0
- spc-grafeno-login@1.0.0
- grafeno-core@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.