LWA-2026-12059 confirmed malware

hatcher-utility-dev@1.0.0

Malicious code in hatcher-utility-dev (npm)

T1059.007 · JavaScriptT1552.001 · Credentials In Files

Analysis

The package's postinstall hook (scripts/postinstall.js) runs on every install and serializes the installer's entire process environment (including any NPM_TOKEN, GITHUB_TOKEN, AWS credentials, and other secrets present at install time) into KEY=VALUE lines, writing them to ./env.hat in the package install directory with mode 0600. The README claims the hook is gated to Linux hosts with an existing /home/hatch directory, but the code performs no such check: it writes the environment dump unconditionally. The harvested file is not the file the package's own CLI reads, so the write serves no functional purpose other than collecting the installer's environment into a file.

analyzed by
Leitwacht
first seen
Sep 11, 2026, 06:16 PM
analyzed
Sep 11, 2026, 06:17 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.