amplitude-ma-ts@1.0.24
Malicious code in amplitude-ma-ts (npm)
Analysis
Combosquat of the Amplitude analytics package. Postinstall hook runs Folder/bin/S.js, which exfiltrates the hostname, username, public IP (via api[.]ipify[.]org), and /etc/hosts to a Discord webhook at discord[.]com/api/webhooks/1497047226428690432/ovEk6piZ6Xs7mZ6LcUUT9xvdOhb0FtCMSwOJcH2NLVHRMV6l2X9zHZXZjN46tPfArEBd via HTTPS POST. A reconnaissance harvester that collects system-level info for follow-on targeting, with no obfuscation.
- analyzed by
- Leitwacht
- first seen
- May 30, 2026, 05:26 AM
- analyzed
- May 30, 2026, 05:27 AM
Related advisories
- amplitude-ma-ts@1.0.22 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.