mypocmaliciouspackage-cursorpt1@4.0.0
Malicious code in mypocmaliciouspackage-cursorpt1 (npm)
T1059.004 · Unix ShellT1552.005 · Cloud Instance Metadata APIT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The preinstall script steals GCP metadata service-account credentials: it curls hxxp://metadata[.]google[.]internal/computeMetadata/v1/instance/service-accounts/230183572078-compute/token with the Metadata-Flavor: Google header, captures the token, then POSTs it to hxxps://webhook-test[.]com/600362a259dbe7e193c2f8508876ab18 — cloud metadata credential theft and exfiltration. The package has no code files (just package.json, ~416 bytes), consistent with a payload-only namespace-claim attack.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 12:14 AM
- analyzed
- Jun 11, 2026, 12:14 AM
Related advisories
- simple-date-formatter-util-11@1.0.0
- simple-date-formatter-util-4@1.0.0
- string-formatter-pro@1.0.0
- ripshakti@80.0.0
- anthropic-internal-tools@1.0.0
- date-format-helper2@1.0.4
- hunsterx-package@7.0.1
- delta-time-32bb@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.