os-ulid-void@3.0.2
Malicious code in os-ulid-void (npm)
Analysis
os-ulid-void@3.0.2 is a combosquat of the legitimate ulid package. Published by ernestmaxwell545 (gmail) impersonating author Alizain Feerasta. Postinstall (dist/utils.mjs) contains: anti-VM CPU-count check, detached background fork, copies 949KB payload.js to persistent directory, and sets up OS persistence across Win (schtasks/reg Run key/VBS), Linux (systemd user service/XDG autostart), and macOS (launchd). Payload.js is a full infostealer: exfiltrates .env/credentials/wallet files, captures keystrokes and clipboard, steals browser profiles and environment variables, and POSTs to XOR-obfuscated C2 at /api/validate/{files,project-env,tdata/upload,ps-history,wallets,keyboard-events}. No [redacted-marker] marker found.
- analyzed by
- Leitwacht
- first seen
- Jun 9, 2026, 03:34 AM
- analyzed
- Jun 9, 2026, 03:35 AM
Related advisories
- gpt-terminal-cli@1.0.0
- wormgpt-cli@1.0.1
- ts-eslint-jest@1.0.0
- jest-formatter@1.0.0
- express-mongo-limit@2.0.1
- pinokio-redis@1.0.127
- zredis-typed@1.0.127
- zod-pino434@1.0.127
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.