opentelemetry-contrib-scripts@55.33.111
Malicious code in opentelemetry-contrib-scripts (npm)
Analysis
opentelemetry-contrib-scripts@55.33.111 is a version-bump combosquat of OpenTelemetry with no README, description, or repository URL and a nonsensical version (55.33.111). Its postinstall hook writes hostname, platform, and architecture into a stealthy hidden directory (~/.local/share/package-install/ on Linux/macOS, %LOCALAPPDATA%\Proofs\package-install\ on Windows) and drops a dummy helper script with execute permissions. This version performs no network exfiltration, consistent with an incomplete/staged supply-chain payload that fingerprints the host on install.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 09:14 PM
- analyzed
- Jun 11, 2026, 09:16 PM
Related advisories
- mongodb-example@55.33.111
- vps-adapter-core@1.0.0
- web3-core-utils@4.3.5
- rollup-packages-polyfill-core@0.5.0
- opentelemetry-plugin-graphql-example@55.33.111
- openclaw-preview@2026.6.1
- worker-build@9.0.1
- index-ulid@3.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.