renovate-config-doctolib@9.9.16
Malicious code in renovate-config-doctolib (npm)
Analysis
Version-squatting package impersonating renovate-config-doctolib (a Renovate shared config). Its preinstall hook (scripts/audit.js) reads ~/.npmrc to extract registry URLs and tokens, collects the installer's hostname, username, platform, git remote URLs, and Windows AD domain environment variables. All stolen data is base64-encoded into a single query string and sent via HTTPS GET to baoreqygjveumkkxydcd[.]supabase[.]co/functions/v1/Webhook_OOB, a Supabase Edge Function acting as the C2 collector. The C2 hostname is obfuscated via base64 decoding at runtime to bypass static analysis. The package exfiltrates its installer's npm registry credentials, git metadata, and host identity — enabling downstream token theft, package hijacking, and lateral movement into the victim's CI/CD supply chain.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 05:23 AM
- analyzed
- Jun 13, 2026, 05:25 AM
Related advisories
- coral-wraith@1.0.4
- internallib_v557@1.0.5
- noon-contracts@1.0.0
- ecto-nightly-spirit@1.0.6
- ts-ecro@0.0.6
- farming-tools-12@4.68.54
- wallet-sdk-9@3.7.73
- simple-date-formatter-util-14@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.