LWA-2026-1296 MAL-2026-3028 ↗ confirmed malware

amplitude-ma-ts@1.0.22

Malicious code in amplitude-ma-ts (npm)

Analysis

Combosquat of the Amplitude analytics package. Both v1.0.22 and v1.0.24 ship an identical postinstall script (Folder/bin/S.js) that collects the hostname, USER, cwd, public IP (via api[.]ipify[.]org using curl), and the contents of /etc/hosts, then exfiltrates all of it as a JSON embed via POST to a Discord webhook (discord[.]com/api/webhooks/1497047226428690432/...). Plain-text data theft via lifecycle hook with no obfuscation.

analyzed by
Leitwacht
first seen
May 30, 2026, 05:26 AM
analyzed
May 30, 2026, 05:27 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.