bmc-translate-utils@1.1.1
Malicious code in bmc-translate-utils (npm)
T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1071.001 · Web Protocols
Analysis
The package's preinstall hook runs a 499KB obfuscated script (index.js) that harvests the installer's GitHub token and validates it against the GitHub API. The script reads a GitHub token, sends it as an `Authorization: token <value>` header to the GitHub API endpoints /user and /user/orgs, and checks whether the token has repo/workflow scopes and enumerates the account's organizations — reconnaissance for a token-harvesting worm. This behaviour is unrelated to the package's declared purpose as a translation library.
- analyzed by
- Leitwacht
- first seen
- Sep 7, 2026, 09:25 AM
- analyzed
- Sep 7, 2026, 09:26 AM
Related advisories
- multicore-kit@1.1.5
- jwt-logger@2.1.9
- eth-query-utils@1.0.0
- eth-lib-helpers@1.0.0
- gas-price-checker@1.0.0
- @lekzo_dev/amprem@1.0.4
- afhmxiewpsf@1.0.0
- 2nestjs@0.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.