pocbitbarrontest@1.0.0
Malicious code in pocbitbarrontest (npm)
Analysis
A credential-stealing implant with persistent Discord C2. The postinstall hook (node scripts/collect.js) performs comprehensive credential harvesting: it reads browser saved passwords via a Python helper (Chrome/Brave/Edge AES-GCM + DPAPI decryption), steals Discord tokens from LevelDB, scrapes Telegram sessions, reads ~/.aws/credentials, GCloud/Azure configs, the macOS Keychain, SSH private keys, and .env files containing API keys (Stripe, AWS, GitHub). It fingerprints the host via hxxps://api.ipify[.]org and exfiltrates everything to a Discord webhook as an embed with file attachments. It then spawns agent.js as a detached background process — a full C2 implant that connects to Discord's Gateway WebSocket, listens for commands in a C2 channel, and supports remote screenshot capture, file exfiltration from Documents/Desktop, and downloading and executing arbitrary payloads.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 09:57 AM
- analyzed
- Jun 12, 2026, 09:58 AM
Related advisories
- wormgpt-cli@1.0.1
- beaver-ui-side-navigation@35.7.1
- devplatform-spa-plugin-location@35.9.2
- pino-pretty-logger@1.1.1
- packageuwu@1.0.1
- gekko-mev-bot@1.0.0
- system-performance-helper@1.0.1
- react-fontawesome-icons@1.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.