ect-839201@100.0.1
Malicious code in ect-839201 (npm)
T1059.004 · Unix ShellT1005 · Data from Local SystemT1041 · Exfiltration Over C2 Channel
Analysis
The preinstall hook in this package reads /flag.txt from the host and exfiltrates it: it first tries to copy it to web-accessible static directories (/app/public/static/flag.txt, /app/static/flag.txt), and if both fail it uses curl to POST the file content to an attacker-controlled IP (10[.]107[.]121[.]85:8000/flag). The package is version 100.0. This is a flag-stealing payload targeting environments where a /flag.txt exists.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 09:03 AM
- analyzed
- Jun 12, 2026, 09:05 AM
Related advisories
- pie-docs@4.31.0
- openclaw-preview@2026.6.1
- internallib_v856@99.0.0
- chalk-plus-ts@1.0.3
- ecto-rust-read-f3a9c1@1.0.2
- noon-contracts@1.0.0
- node-env-resolver-vite@2.4.2
- pocteszep@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.