LWA-2026-5296 MAL-2026-5779 ↗ confirmed malware

hemi-supply-cron@999.0.0

Malicious code in hemi-supply-cron (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package hemi-supply-cron@999.0.0 runs a preinstall script (postinstall.js) on npm install. The script collects the hostname, current username, working directory, and environment variables matching secret-related keywords (key, secret, token, password, private, ssh, deploy, auth, api, rpc, wallet, sentry, docker, graph, slack, host) — including npm tokens, cloud API keys, and wallet credentials. The harvested data is exfiltrated via HTTPS POST to 185[.]130[.]46[.]35:8443/collect. Errors are silently suppressed. This is a dependency-confusion / version-squat package with a 1017-byte payload designed to steal installer credentials and secrets from CI and local environments.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 03:17 AM
analyzed
Jun 15, 2026, 03:18 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.