LWA-2026-11929 MAL-2026-16025 ↗ confirmed malware

bmc-i18n-extract-cli@1.1.1

Malicious code in bmc-i18n-extract-cli (npm)

T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1195.002 · Compromise Software Supply Chain

Analysis

The package's preinstall hook runs a 499KB obfuscated JavaScript payload (package/index.js) that harvests the installer's GitHub credentials and uses them to self-propagate. The payload validates the stolen token against the GitHub API, checks that it has `repo` and `workflow` scopes, and enumerates the user's organizations and token expiry — the reconnaissance needed to re-publish malicious packages to repositories the victim can write to. The payload is obfuscated with a large encoded string array and a custom RC4/PBKDF2 decoder, and its command-and-control base URL is decoded at runtime from that array. The legitimate CLI code ships separately under dist/; the root index.js is an unrelated malicious install-time payload.

analyzed by
Leitwacht
first seen
Sep 7, 2026, 09:29 AM
analyzed
Sep 7, 2026, 09:30 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.