sheratan_haha@1.0.0
Malicious code in sheratan_haha (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1195.002 · Compromise Software Supply Chain
Analysis
Malicious package published by a known bad actor (same email who published the confirmed-malicious sheratan_test_p). The postinstall hook runs exec('whoami') and exfiltrates the output via HTTPS POST to webhook[.]site/0ea9eb45-3ede-4cf0-9ea9-2b8d700272e7 — a classic beacon/exfiltration pattern. The package misrepresents itself as "A simple date formatting utility" but ships no functional code (main.js is 0 bytes). It also depends on the publisher's own known-malware package sheratan_test_p, compounding the supply-chain risk.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 05:30 AM
- analyzed
- Jun 13, 2026, 05:30 AM
Related advisories
- renovate-config-doctolib@9.9.16
- redux-init-rce@1.0.0
- redux-probe-unknown-action-rce@1.0.0
- houzidawang806@1.0.1
- @ci-lifecycle-test/postinstall-ping@1.0.0
- redeem-onchain-sdk@1.0.1
- eslint-plugin-mistica-local-rules@19.12.11
- qr-code-styling-temp@9.9.10
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.