spectral-corsair@999.999.1000
Malicious code in spectral-corsair (npm)
Analysis
The package spectral-corsair@999.999.1000 is a dependency-confusion stub (version 999.999.1000) that executes install.js on install/postinstall. It searches for CTF flag values in files (/flag, /root/flag, /tmp/flag, ./flag), environment variables (FLAG, FLAG_HTB, HTB_FLAG), and /proc/self/environ, then exfiltrates any captured flag to the C2 host 94[.]237[.]48[.]51:46517 via HTTP PUT to /api/modules/ECT-987654 and HTTP GET to /api/debug?flag=... It also writes the flag to disk at /tmp/spectral_corsair_flag.txt, /tmp/flag.txt, ./flag.txt, and /var/tmp/flag.txt, and outputs it to stdout/stderr for log capture. When no flag is found, it lists the root directory contents for reconnaissance.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 04:33 AM
- analyzed
- Jun 14, 2026, 04:35 AM
Related advisories
- sort-btree@2.1.4
- solanarpclampweb3@1.0.3
- sjs-builders@1.0.4
- sickle-wrapper@0.2.0
- self-v8@8.3.9
- seed-to-private@1.0.1
- scoin_setting@1.0.18
- saps_secplayground_npm_ai@1.0.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.