macos-ci-utils@1.0.1
Malicious code in macos-ci-utils (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1140 · Deobfuscate/Decode Files or InformationT1564.001 · Hidden Files and DirectoriesT1480 · Execution Guardrails
Analysis
On require(), macos-ci-utils@1.0.1 base64-decodes a URL pointing to api[.]ingress-hub[.]com/cdn/assets/update.pkg, downloads that file to a hidden directory (~/Library/Application Support/.node_cache/.runtime), makes it executable, and spawns it as a detached background process (detached:true, child.unref()). All of this is gated on os.platform() === 'darwin' — the payload is inactive on non-macOS systems. This is a remote binary downloader that delivers and executes an unknown payload from a non-standard host.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 04:17 AM
- analyzed
- Jun 13, 2026, 04:18 AM
Related advisories
- index-ulid@3.0.2
- obfus-jsxy@3.2.0
- ecto-rust-read-f3a9c1@1.0.2
- devplatform-spa-plugin-module-loader@35.8.5
- entropyeasybots@2.0.2
- @marketfront/bannerpopup@7.0.0
- @digitalcnzz/embedded-sdk@1.0.7
- util-free-ports@3.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.