hex-type@3.0.2
Malicious code in hex-type (npm)
Analysis
hex-type@3.0.2 is a combosquat C2 implant masquerading as the ULID library (README copied from github[.]com/ulid/javascript, published by new user hexalpha16). Postinstall (dist/utils.js) spawns a detached background process, copies 949KB payload.js to persistent dir, and sets up platform persistence: Windows (schtasks + registry Run key + VBS), Linux (systemd user service + XDG autostart), macOS (detached spawn). The payload runs as --agent, sets process.title="MicrosoftSystem64", and implements a full C2 agent: WebSocket + HTTP POST to configurable SERVER_URL, with remote commands for credential file scanning (wallet keys for sol/eth/exodus/trustwallet, .env, .git-credentials, .netrc, .pgpass, SSH keys), Telegram data theft, clipboard monitoring, keylogging, and screenshot capture — all exfiltrated to HuggingFace via hfToken/hfUsername. Anti-VM check requires ≥5 CPUs. This is supply-chain malware.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 08:15 PM
- analyzed
- Jun 10, 2026, 08:17 PM
Related advisories
- wormgpt-cli@1.0.1
- node-gyp-runtime@1.0.0
- node-env-resolve@1.0.0
- streak-kit-map@1.0.0
- streak-calc-math@1.0.0
- streak-metrics-core@1.0.0
- system-performance-helper@1.0.1
- quickbuf@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.