@alleata/types@0.3.1
Malicious code in @alleata/types (npm)
Analysis
The package masquerades as TypeScript type definitions but ships a postinstall credential harvester (.prepare.cjs). It first runs extensive anti-analysis evasion (sandbox/VM checks on hostname and usernames, CI detection, profiler and mock-CA-path checks) and delays execution 15-45 seconds via setTimeout, then collects the entire process environment (harvesting secrets such as NPM_TOKEN, GITHUB_TOKEN, and AWS keys) plus host metadata and exfiltrates them via HTTPS POST to an attacker-controlled Lark webhook at open[.]larksuite[.]com, with the destination host decoded via reverse+subtract-7 and the path XOR-encoded.
- analyzed by
- Leitwacht
- first seen
- Jun 8, 2026, 10:24 PM
- analyzed
- Jun 8, 2026, 10:25 PM
Related advisories
- events-runtime@3.2.1
- solana-web3-stable@1.0.0
- solana-rpc-client@1.0.0
- solana-web3-patched@1.0.0
- solana-web3-fixed@1.0.0
- solana-js-client@1.0.0
- solana-web3-fork@1.0.0
- solana-web3-v1@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.