@praveenvjpm/color-utils-7210@1.0.0
Malicious code in @praveenvjpm/color-utils-7210 (npm)
Analysis
@praveenvjpm/color-utils-7210@1.0.0 contains no library code — only a package.json and an install.js — and declares a preinstall hook ("node install.js") that executes automatically on npm install. The hook performs host reconnaissance (os.hostname(), process.cwd(), USER/USERNAME), reads the contents of /flag, /flag.txt, /app/flag, /home/node/flag and /tmp/flag, and exfiltrates the combined result over HTTP PUT to hxxp://154[.]57[.]164[.]66:39270/api/modules/<id> for four hardcoded module ids (ECT-987654, ECT-472839, ECT-654321, ECT-839201). The stolen data is wrapped in a YAML "ecto_module" manifest with version "pwned" and power_level "CURSED". Network errors are silently swallowed. The package's stated purpose (color conversion utilities) does not match its contents, and the install hook is its only behaviour.
- analyzed by
- Leitwacht
- first seen
- Oct 7, 2026, 01:16 PM
- analyzed
- Oct 7, 2026, 01:16 PM
Related advisories
- dotenv-runtime@1.0.0
- hardhat-promised@2.21.0
- @pinecone-experience/messages@99.9.1
- solidity-gas-watcher@2.21.0
- nebulaai-sdk@1.0.0
- envparse2@1.0.1
- @shared-runtime/modules@9.9.10
- sbironman@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.