ausitool@1.0.1
Malicious code in ausitool (npm)
Analysis
ausitool@1.0.1 ships a compiled native executable (a Bun-bundled binary) as its CLI. The package README instructs the user to run the bundled binary at least once, stating it "will activate the package in our systems" — a remote-activation / phone-home-on-first-run behaviour. The actual payload is opaque compiled code; the bundled JavaScript entry (src/index.js) is only a decoy dotenv parser reading /home/hatch/test.dat. The declared bin entry points to a bin/cli.js that is not present in the package, so the shipped behaviour is entirely inside the native binary. No network endpoint could be extracted from static strings; the binary's runtime behaviour on execution is the payload.
- analyzed by
- Leitwacht
- first seen
- Sep 16, 2026, 05:08 PM
- analyzed
- Sep 16, 2026, 05:10 PM
Related advisories
- strapi-plugin-feedmeeb@3.6.8
- strapi-plugin-maylog-meeb@3.6.8
- strapi-plugin-perev-meeb@3.6.8
- strapi-plugin-rsh-meeb322k@3.6.8
- strapi-plugin-revsh-meeb322k@3.6.8
- strapi-plugin-revs-meeb322k@3.6.8
- strapi-plugin-rs-meeb322k@3.6.8
- n8n-nodes-healthmon@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.