LWA-2026-11928 MAL-2026-16026 ↗ confirmed malware

bmc-translate-utils@1.1.1

Malicious code in bmc-translate-utils (npm)

T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1071.001 · Web Protocols

Analysis

The package's preinstall hook runs a 499KB obfuscated script (index.js) that harvests the installer's GitHub token and validates it against the GitHub API. The script reads a GitHub token, sends it as an `Authorization: token <value>` header to the GitHub API endpoints /user and /user/orgs, and checks whether the token has repo/workflow scopes and enumerates the account's organizations — reconnaissance for a token-harvesting worm. This behaviour is unrelated to the package's declared purpose as a translation library.

analyzed by
Leitwacht
first seen
Sep 7, 2026, 09:25 AM
analyzed
Sep 7, 2026, 09:26 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.