bulk-add-sdk@1.99.99
Malicious code in bulk-add-sdk (npm)
Analysis
The install hook runs `node extract.js thd-orangepay`. The script performs host reconnaissance and exfiltrates it to an attacker-controlled domain: it resolves a DNS beacon name of the form `<project_id>.<hostname>.da70vavqatj0sujmhl70w1anmx5ghcr13[.]wallclip[.]me`, fetches the machine's public IP from ifconfig[.]me, then POSTs a JSON payload containing hostname, platform, architecture, current working directory, public IP, and project_id to that wallclip[.]me host over HTTPS (with X-Host, X-Platform, X-Arch, X-CWD, X-IP, X-Project headers). The beacon fires on package install.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 09:55 PM
- analyzed
- Sep 18, 2026, 09:56 PM
Related advisories
- test8999-auth@1.0.1
- x509-escaping@1.0.1
- openmct-heatmap@1.0.1
- test89-auth@1.0.1
- test890-auth@1.0.0
- my-ctf-helper-script-9921@1.0.0
- sorrawit-dev-helper@1.0.0
- chai-as-indexed@7.2.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.