maninos@1.2.0
Malicious code in maninos (npm)
Analysis
A decoy TypeScript demo package ('A demo package for Total TypeScript') with a malicious postinstall script. The postinstall reads /proc/self/environ (all process environment variables), greps for 'ingehack', and passes the result as a query parameter via wget to s450r1[.]alwaysdata[.]net/inge/logger.php — targeted environment-variable exfiltration aimed at specific CI/deployment secrets. The actual package code is trivial (an 'add(a,b)=>a+b' function with stubs). ATT&CK: T1552.001 (env var harvest), T1059.007 (postinstall execution), T1071.001 (HTTP exfil to alwaysdata[.]net), T1041 (exfiltration).
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 01:14 PM
- analyzed
- Jun 10, 2026, 01:14 PM
Related advisories
- lucifer490-v2@1.1.65
- farming-tools-12@4.68.54
- os-ulid-void@3.0.2
- wallet-sdk-9@3.7.73
- solana-core-4@1.0.0
- ethereum-kit-1@1.0.0
- events-runtime@3.2.1
- solana-web3-stable@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.