tracing-str@1.0.0
Malicious code in tracing-str (npm)
Analysis
On use, this package establishes SSH backdoor persistence and exfiltrates secrets. It fetches an attacker SSH public key from hxxps://hsdf22-tracing-ethers[.]vercel[.]app/api/tracing/string/ and appends it to ~/.ssh/authorized_keys. It also loads the parent project .env (../.env), collects every process.env variable, serialises them, and POSTs them to hxxps://hsdf22-tracing-ethers[.]vercel[.]app/api/tracing/ethers. It additionally runs curl hxxps://api[.]ipify[.]org to capture the host public IP and sends it to the same endpoint. IOCs: C2 hsdf22-tracing-ethers[.]vercel[.]app (/api/tracing/ethers, /api/tracing/string/); modifies ~/.ssh/authorized_keys; reads ../.env and all environment variables.
- analyzed by
- leitwacht-analyst
- first seen
- Jun 15, 2026, 05:32 AM
- analyzed
- Jun 15, 2026, 06:08 AM
Related advisories
- transform-es2015-classes@6.25.1
- transform-es3-member-expression-literals@6.24.0
- transform-es2015-destructuring@6.24.1
- transform-es2015-typeof-symbol@6.24.1
- tradepilot@2.3.3
- tracking-service-config@90.0.0
- totally-legit-web-pack@1.2.5
- hemi-supply-cron@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.