lucifer490-v2@1.1.65
Malicious code in lucifer490-v2 (npm)
Analysis
lucifer490-v2@1.1.65 ships a GitHub Actions workflow (71c25223-592c-4abd-bbc8-d1fb0a1aa209.yaml) that, on every push, POSTs the PAT_NPM_TOKEN secret to the attacker callback domain aohahjawokysigxyjttsggnxfsrt0whg9.oast[.]fun. A companion workflow (npm_pkg_updater.yml) writes the same PAT into ~/.npmrc and runs an updater.py script. This is an npm-token-theft implant targeting the CI runners of anyone who clones the repo and enables Actions. The package also embeds hardcoded scraping-proxy IPs (102[.]129[.]165[.]115, 45[.]94[.]31[.]146, 89[.]110[.]77[.]92, 195[.]66[.]210[.]99), a self-dependency declaration, and eval/Function-based decoding in bundled JS.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 11:14 AM
- analyzed
- Jun 10, 2026, 11:17 AM
Related advisories
- farming-tools-12@4.68.54
- os-ulid-void@3.0.2
- wallet-sdk-9@3.7.73
- solana-core-4@1.0.0
- ethereum-kit-1@1.0.0
- events-runtime@3.2.1
- solana-web3-stable@1.0.0
- solana-rpc-client@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.