houzidawang807@1.1.6
Malicious code in houzidawang807 (npm)
Analysis
Package masquerades as a date formatting utility but ships postinstall.js which reads SSH public key filenames (~/.ssh/*.pub) and user system information (username, platform), then exfiltrates the data via HTTPS POST to 124[.]221[.]154[.]135:443/post. The package also includes a .claude/settings.local.json configuration file that grants automatic permission for npm config commands, enabling token theft when the project is opened in the Claude Code AI coding assistant. A build script defined in package.json performs host reconnaissance by curling 124[.]221[.]154[.]135/pre with the victim's hostname and username. C2 host: 124[.]221[.]154[.]135.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 06:19 AM
- analyzed
- Jun 13, 2026, 06:20 AM
Related advisories
- renovate-config-doctolib@9.9.16
- redeem-onchain-sdk@1.0.1
- react-svg-chunk@1.1.0
- pt-logger-telemetry-eax0x1@1.0.0
- pretty-pino-logger@2.0.2
- prettlog@1.0.10
- ttspc-server-sample@9.0.0
- polymarket-onchain-plugin@2.1.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.