LWA-2026-12060 MAL-2026-16464 ↗ confirmed malware

hachutis@1.0.0

Malicious code in hachutis (npm)

T1059.007 · JavaScriptT1552.001 · Credentials In Files

Analysis

The postinstall hook (scripts/postinstall.js) dumps the full process environment — every environment variable present in the installer's shell, including any npm/GitHub/cloud tokens — into a file named env.hat in the package install directory. The package's declared CLI binary (hatcher-env) points to a bin/cli.js file that is not shipped, so the install-time environment dump is the package's only functional behaviour.

analyzed by
Leitwacht
first seen
Sep 11, 2026, 06:24 PM
analyzed
Sep 11, 2026, 06:25 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.