LWA-2026-11950 MAL-2026-16082 ↗ confirmed malware

@umschool/platform@999.0.0

Malicious code in @umschool/platform (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1552.001 · Credentials In FilesT1552.004 · Private KeysT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The postinstall hook (postinstall.js) of @umschool/platform@999.0.0 is a credential harvester. On install it reads the Kubernetes service-account token, namespace, and CA from /var/run/secrets/kubernetes[.]io/serviceaccount/, fetches AWS and Yandex cloud metadata credentials from the 169[.]254[.]169[.]254 metadata endpoints (IAM security-credentials and computeMetadata token paths), enumerates the full process environment for variables matching token/secret/key/pass/auth/db/url/host/api/aws/yc/k8s/kube, reads .env files up five directory levels, reads /etc/hosts and /etc/resolv.conf, and queries the Kubernetes API using the stolen service-account token. All collected data is base64-encoded and POSTed to the callback host akko[.]requestcatcher[.]com over HTTPS with certificate verification disabled. The package self-describes as a dependency-confusion proof-of-concept but actually exfiltrates credentials, tokens, environment variables, and files.

analyzed by
Leitwacht
first seen
Sep 9, 2026, 05:18 AM
analyzed
Sep 9, 2026, 05:20 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.