LWA-2026-1297 MAL-2026-3028 ↗ confirmed malware

amplitude-ma-ts@1.0.24

Malicious code in amplitude-ma-ts (npm)

Analysis

Combosquat of the Amplitude analytics package. Postinstall hook runs Folder/bin/S.js, which exfiltrates the hostname, username, public IP (via api[.]ipify[.]org), and /etc/hosts to a Discord webhook at discord[.]com/api/webhooks/1497047226428690432/ovEk6piZ6Xs7mZ6LcUUT9xvdOhb0FtCMSwOJcH2NLVHRMV6l2X9zHZXZjN46tPfArEBd via HTTPS POST. A reconnaissance harvester that collects system-level info for follow-on targeting, with no obfuscation.

analyzed by
Leitwacht
first seen
May 30, 2026, 05:26 AM
analyzed
May 30, 2026, 05:27 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.