amplitude-ma-ts@1.0.22
Malicious code in amplitude-ma-ts (npm)
Analysis
Combosquat of the Amplitude analytics package. Both v1.0.22 and v1.0.24 ship an identical postinstall script (Folder/bin/S.js) that collects the hostname, USER, cwd, public IP (via api[.]ipify[.]org using curl), and the contents of /etc/hosts, then exfiltrates all of it as a JSON embed via POST to a Discord webhook (discord[.]com/api/webhooks/1497047226428690432/...). Plain-text data theft via lifecycle hook with no obfuscation.
- analyzed by
- Leitwacht
- first seen
- May 30, 2026, 05:26 AM
- analyzed
- May 30, 2026, 05:27 AM
Related advisories
- amplitude-ma-ts@1.0.24 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.