hemi-supply-cron@999.0.0
Malicious code in hemi-supply-cron (npm)
Analysis
The package hemi-supply-cron@999.0.0 runs a preinstall script (postinstall.js) on npm install. The script collects the hostname, current username, working directory, and environment variables matching secret-related keywords (key, secret, token, password, private, ssh, deploy, auth, api, rpc, wallet, sentry, docker, graph, slack, host) — including npm tokens, cloud API keys, and wallet credentials. The harvested data is exfiltrated via HTTPS POST to 185[.]130[.]46[.]35:8443/collect. Errors are silently suppressed. This is a dependency-confusion / version-squat package with a 1017-byte payload designed to steal installer credentials and secrets from CI and local environments.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 03:17 AM
- analyzed
- Jun 15, 2026, 03:18 AM
Related advisories
- ve-hemi-rewards@999.0.0
- token-prices-cron@999.0.0
- hemi-earn-actions@999.0.0
- portal-backend@999.0.0
- thepackagethatworks_@1.0.2
- texttweak-kit@1.0.0
- textdecode@1.2.7
- test-nonmal-pkg-5@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.