period-newline@0.1.0
Malicious code in period-newline (npm)
Analysis
period-newline@0.1.0 poses as a tiny text formatter (inserts newlines after periods) but ships a malicious postinstall hook (dist/index5_test.js). On install, the hook: (1) self-deletes and overwrites package.json with a dummy — evasion; (2) AES-256-CTR decrypts embedded payload strings revealing a TCP C2 endpoint, credential-target paths, and an AES-GCM encryption key; (3) reads ~/.ssh/id_rsa, ~/.aws/credentials, ~/.docker/config.json, ~/.npmrc, ~/.netrc, Chrome Login Data, .env files, and git history; (4) collects hostname, username, and external IP from api[.]ipify[.]org; (5) encrypts all stolen data with AES-GCM and exfiltrates over TCP to the C2. Publisher ([account] The legitimate-looking README and CLI are a decoy for a full credential-theft implant.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 06:14 AM
- analyzed
- Jun 12, 2026, 06:15 AM
Related advisories
- weight2loss@1.0.5
- gpt-terminal-cli@1.0.0
- system-performance-helper@1.0.1
- decimal-format-core@3.5.4
- mailconfirmer@3.3.11
- velocityfix@1.0.0
- node-core-libs@1.0.0
- ordered-btree@3.2.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.