umi-preset-rce-jytest@1.0.1
Malicious code in umi-preset-rce-jytest (npm)
Analysis
An Umi.js build plugin that harvests system and environment information during the build phase. When a project using this dependency is built, the plugin executes shell commands to collect: hostname, username, current working directory, Node/npm versions, the full environment variable listing (capturing any CI/CD tokens such as NPM_TOKEN, GITHUB_TOKEN, or AWS credentials present in the environment), network configuration, process list, disk usage, network connections, /etc/passwd (first 20 lines), and /etc/hosts. All collected data is written to a file named rce-debug.log in the build output directories (dist, build, out, output, public). Additionally, the data is base64-encoded and injected as an HTML comment (prefixed JYRCE::) into every .html file in those directories. No outbound network traffic was observed from this package itself; the stolen data is exfiltrated through contaminated build artifacts.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 10:42 AM
- analyzed
- Jun 15, 2026, 10:44 AM
Related advisories
- ts-relayer-pub@1.0.0
- tiny-string-parser@0.1.2
- third-sender@1.0.0
- tg-msg-effect@1.0.10
- testzapier@1.0.0
- stylelint-standard@1.2.0
- sjs-builders@1.0.4
- sisubeny-bun-pwn-payload-1@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.