alkajsdfoiwqeusdflkjsdf@3.7.3
Malicious code in alkajsdfoiwqeusdflkjsdf (npm)
Analysis
The preinstall hook (node index.js) runs before install and exfiltrates installer data to the remote host l2ha5tswnm71286wnjgrngvb4tyejmdpe[.]i[.]dr0gas[.]com. It first POSTs host metadata (home directory, hostname, username, DNS servers, package.json) to the host root path, then POSTs the full process environment (process.env, containing tokens and credentials such as NPM_TOKEN, GITHUB_TOKEN, and cloud keys) as JSON to hxxps://l2ha5tswnm71286wnjgrngvb4tyejmdpe[.]i[.]dr0gas[.]com/exf. The package name is a random string and the version is 3.7.3, consistent with a dependency-confusion attack.
- analyzed by
- Leitwacht
- first seen
- Sep 14, 2026, 11:02 PM
- analyzed
- Sep 14, 2026, 11:03 PM
Related advisories
- n8n-nodes-sysdiag@1.0.0
- concierge-sdk@99.99.99
- hachutis@1.0.0
- hatcher-utility-dev@1.0.0
- cr-bot-common@1.0.0
- soltinel-pro@0.2.2
- gmgn-trading-kit@1.7.0
- @davidov0516/string-utils@1.1.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.