event-hunter@1.0.0
Malicious code in event-hunter (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols
Analysis
The package declares itself a dependency-confusion RCE artifact. Its postinstall hook runs index.js, which collects the host's hostname and install timestamp and sends them base64-encoded to the remote endpoint hxxps://estimator-nemeses-unwatched[.]ngrok-free[.]dev/canary on every install, exfiltrating host metadata to an attacker-controlled tunnel.
- analyzed by
- Leitwacht
- first seen
- Sep 23, 2026, 10:27 AM
- analyzed
- Sep 23, 2026, 10:28 AM
Related advisories
- com.apple.unityplugin.storekit@1.0.1
- @memtensor/memos-cloud-openclaw-plugin@0.1.23
- my-company-device@0.1.0
- efhthrthrthregerht@99.9.9
- faceplate-docs@99.9.9
- eslint-plugin-i18n-shreddit@99.9.9
- @tvg-mar/utils@9.9.10
- @tvg-mar/tvg-promos-atomic-ui@9.9.10
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.