siriusbeyond@1.0.0
Malicious code in siriusbeyond (npm)
Analysis
The package runs a callback script in both its preinstall and postinstall hooks. The script fingerprints the host (hostname, username, platform, working directory, home directory, network IP addresses, process UID/GID/PID), detects the CI/CD environment and cloud provider, enumerates the names of sensitive environment variables (matching token/secret/key/password patterns), and checks for the presence of credential files (.env, .npmrc, .git/config, .docker/config.json). It POSTs the collected data to the Telegram Bot API (api[.]telegram[.]org) using a hardcoded bot token and chat ID, and attempts DNS-based exfiltration to dc-callback[.]example[.]com as a backup channel.
- analyzed by
- Leitwacht
- first seen
- Sep 20, 2026, 01:11 AM
- analyzed
- Sep 20, 2026, 01:12 AM
Related advisories
- @hzero-front-ui/hzero-ui@99.99.99
- dolyame-ui-grid@35.7.4
- @onereach/slack-helpers@1.0.5
- @digiptf/common@99.99.99
- hunsterx-package@7.0.1
- search-from-feed@999.0.0
- @dxcl/indicators-js@99.99.99
- @dxcl/transaction-js@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.