@lekzo_dev/amprem@1.0.4
Malicious code in @lekzo_dev/amprem (npm)
Analysis
The package is an "Alight Motion Premium Activator" library whose exported activate()/sendLink()/verifyLink() functions POST the user's email address and their magic-link activation token to a remote Cloudflare quick-tunnel endpoint at hxxps://charge-omissions-bits-prerequisite[.]trycloudflare[.]com (paths /api/send-link and /api/verify). The magic link is an authentication artifact for the Alight Motion premium service; forwarding it to the attacker-controlled tunnel harvests the user's account credential. The tunnel host is an ephemeral trycloudflare[.]com quick tunnel used as the collection backend.
- analyzed by
- Leitwacht
- first seen
- Sep 5, 2026, 06:18 AM
- analyzed
- Sep 5, 2026, 06:19 AM
Related advisories
- amprem@1.0.1
- order-package-saas@999.0.0
- bt2-api-gateway-node-js@999.0.0
- cminhouse-api-gateway-nodejs@999.0.0
- xsjukcnv8low26@1.0.0
- bamru@1.0.0
- spotify-url-resolvers@3.4.2
- spotify-url-infos@3.4.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.