index-ulid@3.0.2
Malicious code in index-ulid (npm)
Analysis
index-ulid combosquats the popular ulid npm package. The postinstall hook spawns a detached, hidden child process that copies a 950KB implant (payload.js) to a persistent directory named MicrosoftSystem64 and installs cross-platform persistence (Windows scheduled task/registry Run key, macOS launchd, Linux systemd user service / XDG autostart). The implant XOR-obfuscates its WebSocket and HTTP C2 URLs, checks CPU count as anti-sandbox, and steals credentials from Chrome/Edge/Brave/Firefox browsers, FileZilla, Telegram Desktop, SSH keys, and OneDrive. It dumps all process.env variables (targeting NPM_TOKEN, GITHUB_TOKEN, AWS credentials) and exfiltrates them to the C2 server. The package claims the original ulid author but is published by a different user (probull100).
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 07:07 PM
- analyzed
- Jun 11, 2026, 07:08 PM
Related advisories
- obfus-jsxy@3.2.0
- ecto-rust-read-f3a9c1@1.0.2
- devplatform-spa-plugin-module-loader@35.8.5
- entropyeasybots@2.0.2
- @marketfront/bannerpopup@7.0.0
- @digitalcnzz/embedded-sdk@1.0.7
- util-free-ports@3.1.2
- stringfy-utils-kit@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.