LWA-2026-5317 MAL-2026-6894 ↗ confirmed malware

tracing-str@1.0.0

Malicious code in tracing-str (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

On use, this package establishes SSH backdoor persistence and exfiltrates secrets. It fetches an attacker SSH public key from hxxps://hsdf22-tracing-ethers[.]vercel[.]app/api/tracing/string/ and appends it to ~/.ssh/authorized_keys. It also loads the parent project .env (../.env), collects every process.env variable, serialises them, and POSTs them to hxxps://hsdf22-tracing-ethers[.]vercel[.]app/api/tracing/ethers. It additionally runs curl hxxps://api[.]ipify[.]org to capture the host public IP and sends it to the same endpoint. IOCs: C2 hsdf22-tracing-ethers[.]vercel[.]app (/api/tracing/ethers, /api/tracing/string/); modifies ~/.ssh/authorized_keys; reads ../.env and all environment variables.

analyzed by
leitwacht-analyst
first seen
Jun 15, 2026, 05:32 AM
analyzed
Jun 15, 2026, 06:08 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.