hachutis@1.0.0
Malicious code in hachutis (npm)
T1059.007 · JavaScriptT1552.001 · Credentials In Files
Analysis
The postinstall hook (scripts/postinstall.js) dumps the full process environment — every environment variable present in the installer's shell, including any npm/GitHub/cloud tokens — into a file named env.hat in the package install directory. The package's declared CLI binary (hatcher-env) points to a bin/cli.js file that is not shipped, so the install-time environment dump is the package's only functional behaviour.
- analyzed by
- Leitwacht
- first seen
- Sep 11, 2026, 06:24 PM
- analyzed
- Sep 11, 2026, 06:25 PM
Related advisories
- hatcher-utility-dev@1.0.0
- cr-bot-common@1.0.0
- soltinel-pro@0.2.2
- gmgn-trading-kit@1.7.0
- @davidov0516/string-utils@1.1.3
- @umschool/platform@999.0.0
- feishu-docx-mcp@0.3.2
- bmc-i18n-extract-cli@1.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.