field-plus@99.99.1
Malicious code in field-plus (npm)
Analysis
Dependency-confusion stub. On install, both the preinstall and postinstall lifecycle hooks execute a curl command that sends the victim's username, hostname, and working directory to the hardcoded IP address 3[.]7[.]226[.]146 on TCP port 9000 via HTTP GET to the path /callback. The response is discarded and the exit code is swallowed (redirected to /dev/null with `|| true`), making the beacon silent to the installer. The package ships no functional code — only a package.json containing the hooks at version 99.99.1, a sentinel version chosen to take priority over the legitimate field-plus package in automatic resolution.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 10:29 AM
- analyzed
- Jun 15, 2026, 10:30 AM
Related advisories
- ugent_uws@10.9.11
- ogd-analytics@1.0.0
- nic-datagov@1.0.0
- ts-enum-helper@1.0.0
- tether-base@99.0.0
- tecken@0.1.10
- electron-internal-utils@1.0.0
- skipthedishes_react@0.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.