withnotification@55.33.111
Malicious code in withnotification (npm)
Analysis
The package withnotification@55.33.111 runs a postinstall script that writes host metadata (hostname, OS platform, CPU architecture, installation timestamp) to a hidden directory on disk: ~/.local/share/package-install/ on Linux/macOS, and %LOCALAPPDATA%\Proofs\package-install\ on Windows. It also drops a placeholder script file (helper.sh or helper.exe) into that directory. This host-fingerprinting behavior collects system information for reconnaissance purposes. No network exfiltration is performed in this version, but the local staging pattern is consistent with setting up a persistence/beacon directory for later activation.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 04:43 AM
- analyzed
- Jun 16, 2026, 04:46 AM
Related advisories
- wisdomtreetest@1.0.1
- wind_css@4.0.13
- wime-zle@1.1.4
- web-pool@2.3.5
- check-ulid@3.0.2
- webpack-cdn-fetcher@1.0.1
- web-examples@55.33.111
- web3-core-utils@4.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.