bmc-i18n-extract-cli@1.1.1
Malicious code in bmc-i18n-extract-cli (npm)
Analysis
The package's preinstall hook runs a 499KB obfuscated JavaScript payload (package/index.js) that harvests the installer's GitHub credentials and uses them to self-propagate. The payload validates the stolen token against the GitHub API, checks that it has `repo` and `workflow` scopes, and enumerates the user's organizations and token expiry — the reconnaissance needed to re-publish malicious packages to repositories the victim can write to. The payload is obfuscated with a large encoded string array and a custom RC4/PBKDF2 decoder, and its command-and-control base URL is decoded at runtime from that array. The legitimate CLI code ships separately under dist/; the root index.js is an unrelated malicious install-time payload.
- analyzed by
- Leitwacht
- first seen
- Sep 7, 2026, 09:29 AM
- analyzed
- Sep 7, 2026, 09:30 AM
Related advisories
- bmc-translate-utils@1.1.1
- multicore-kit@1.1.5
- jwt-logger@2.1.9
- eth-query-utils@1.0.0
- eth-lib-helpers@1.0.0
- gas-price-checker@1.0.0
- @lekzo_dev/amprem@1.0.4
- afhmxiewpsf@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.